Wireless penetration testing that secures the airwaves.
Your wireless networks extend the attack surface beyond your walls. SubRosa tests WiFi infrastructure, protocols, and configurations, plus Bluetooth and RF, so an attacker cannot pivot in over the air.
WiFi · WPA2/WPA3 · Rogue AP · Bluetooth · RF
What is wireless penetration testing?
Wireless penetration testing assesses the security of your WiFi and other radio-based networks: encryption and authentication (WPA2, WPA3, 802.1X/EAP), rogue and evil-twin access points, network segmentation, and RF technologies like Bluetooth, RFID, and NFC. The goal is to prove whether an attacker within radio range could get onto your network or pivot deeper, and to close the gaps that let them.
Every wireless vector that matters.
Specialized testing across all the wireless technologies and protocols in your environment.
WiFi security assessment
Encryption analysis, authentication bypass, and configuration review across your enterprise and guest WiFi networks.
Rogue AP & evil twin
Detection and exploitation of rogue and evil-twin access points to validate client behavior and wireless segmentation.
Protocol & enterprise auth
Testing of WPA2 and WPA3, 802.1X, and EAP enterprise authentication for weaknesses that enable unauthorized access.
Bluetooth & RF
Assessment of Bluetooth, RFID, and NFC devices and protocols for flaws in pairing, authentication, and data transmission.
From survey to proven access.
A wireless test answers one question: can someone outside your walls reach inside your network. This is how we establish that.
- 01
Scoping and site survey
We agree sites, networks and whether client-side attacks against staff devices are in scope. Guest networks are included deliberately — they are frequently the weakest segment and frequently assumed to be isolated when they are not.
- 02
Mapping every signal you emit
We survey from your car park and perimeter, mapping every SSID, its reach beyond your building, encryption in use and hidden or forgotten networks. Organisations are regularly surprised by a legacy access point nobody has owned for years.
- 03
Attacking the authentication
WPA2 and WPA3 handshakes, PSK strength, and enterprise authentication including certificate validation and credential relay. Weak EAP configuration that accepts an untrusted certificate is one of the most common and most serious findings we report.
- 04
Rogue access point and evil twin
We stand up a convincing clone of your network and establish whether staff devices connect to it automatically and whether credentials can be captured. This tests device configuration and user behaviour together, which is how the attack actually works.
- 05
What the access reaches
Getting onto the wireless network is only the finding if it leads somewhere. We test what the wireless segment can reach: whether guest is genuinely isolated, whether corporate wireless lands next to production, and how far lateral movement goes.
- 06
Reporting and retest
A report with signal maps, the attacks that succeeded, and configuration-level remediation, plus a complimentary retest once changes are made.
Into the RF attack surface.
RF-aware testing
We test the full radio attack surface, WiFi, Bluetooth, and RF, not just a WiFi password audit, because that is where attackers actually pivot.
Segmentation focus
We validate that a foothold on wireless cannot become a foothold on the rest of the network, testing segmentation and monitoring end to end.
Real exploitation
We safely exploit what we find to prove real impact and confirm your controls hold, rather than handing you a list of theoretical issues.
From report to remediation.
Your wireless pen test findings land in Sable, prioritized, assigned, and tracked from open to retested, so remediation becomes a managed workflow instead of a PDF that gets forgotten.
- CriticalOpenEvil-twin captures corp credsWiFi
- HighIn progressEAP misconfig allows bypass802.1X
- HighRetestedNo isolation from corp VLANGuest
- MediumOpenLegacy pairing on badge readersBluetooth
Common questions
- What is wireless penetration testing?
- Wireless penetration testing assesses the security of your WiFi and other radio-based networks: encryption and authentication (WPA2, WPA3, 802.1X/EAP), rogue and evil-twin access points, network segmentation, and RF technologies like Bluetooth, RFID, and NFC. It proves whether an attacker within radio range could get onto your network or pivot deeper.
- Do you test more than WiFi?
- Yes. Beyond WiFi and enterprise authentication, SubRosa tests the broader RF attack surface, including Bluetooth, RFID, and NFC, and validates that a wireless foothold cannot become a foothold on the rest of the network through weak segmentation.
- Do you need to be on site for a wireless test?
- For most of it, yes. The assessment starts outside your building — car park, street, neighbouring floors — because the point is establishing what an attacker can reach without entering. Some analysis happens remotely afterwards, but the survey itself has to be physically near your estate.
- Is our guest network in scope?
- It should be, and it is frequently where the finding is. Guest networks are widely assumed to be isolated from corporate and reasonably often are not, or are isolated in a way that a single misconfigured rule undoes. We test whether the isolation is real rather than taking the design at its word.
- Does WPA3 mean we are secure?
- It closes several attacks that worked against WPA2 and it is worth deploying. It does not address weak enterprise authentication configuration, devices that connect automatically to a cloned network, forgotten access points nobody owns, or a wireless segment that lands next to production. Those are configuration and architecture problems, and they are what the test is for.
- What about Bluetooth and other RF?
- In scope where you want them. Bluetooth, and where relevant other RF such as badge and building systems, extend the same principle — signal that leaves your building is attack surface, whether or not it is WiFi.
Secure your networks over the air.
Book a wireless penetration test and find out exactly what an attacker within range could reach, and how to shut it down.