Skip to content
Penetration testing
  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation
Security assurance
  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
Managed security
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring
All services on one page
Industries How we work About Blog
1300 AURIAN Contact
Menu
Penetration testing
  • Penetration testing services
  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation
Security assurance
  • Security assurance and compliance services
  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
Managed security
  • Managed security services
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring
  • All services
  • Industries
  • How we work
  • About
  • Blog
Call 1300 AURIAN Contact
  1. Services
  2. Penetration testing
  3. Wireless penetration testing

Penetration testing

Wireless penetration testing

We test your Wi-Fi from the position of someone in range: the car park, the foyer or the unit next door.

Scope a test Call 1300 AURIAN

Who this is for

  • Your Wi-Fi reaches beyond your walls

    Signal does not stop at the property line. Anyone in range, in the car park or the next tenancy, can attempt to reach your network.

  • You run enterprise Wi-Fi across multiple sites

    WPA2 and WPA3-Enterprise depend on certificate validation and configuration that is easy to get subtly wrong across many access points.

  • Staff and guests share the airwaves

    You need confidence that the guest network cannot reach the corporate one, and that a guest cannot become a foothold.

What our wireless penetration test covers

Internet Web application API Perimeter Cloud tenancy Email Office network Workstation Identity Wireless Crown jewels Servers INTERNET: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. WEB APPLICATION: NOT IN SCOPE HERE Covered by web application penetration testing. Click to open that service. API: NOT IN SCOPE HERE Covered by API penetration testing. Click to open that service. PERIMETER: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. CLOUD TENANCY: NOT IN SCOPE HERE Covered by cloud security assessment. Click to open that service. EMAIL: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. OFFICE NETWORK: CHECKS INCLUDE Segmentation from the wireless networks to the wired network What a foothold on Wi-Fi reaches on the LAN WORKSTATION: NOT IN SCOPE HERE Covered by essential Eight assessment. Click to open that service. IDENTITY: NOT IN SCOPE HERE Covered by internal network penetration testing. Click to open that service. WIRELESS: CHECKS INCLUDE WPA2 and WPA3-Enterprise configuration Certificate validation on client devices Rogue and evil-twin exposure Guest isolation and captive portal bypass CROWN JEWELS: NOT IN SCOPE HERE Covered by internal network penetration testing. Click to open that service. SERVERS: NOT IN SCOPE HERE Covered by configuration review and benchmarking. Click to open that service. Internet Web application Perimeter API Email Cloud tenancy Office network Workstation Wireless Identity Crown jewels Servers INTERNET: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. WEB APPLICATION: NOT IN SCOPE HERE Covered by web application penetration testing. Click to open that service. PERIMETER: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. API: NOT IN SCOPE HERE Covered by API penetration testing. Click to open that service. EMAIL: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. CLOUD TENANCY: NOT IN SCOPE HERE Covered by cloud security assessment. Click to open that service. OFFICE NETWORK: CHECKS INCLUDE Segmentation from the wireless networks to the wired network What a foothold on Wi-Fi reaches on the LAN WORKSTATION: NOT IN SCOPE HERE Covered by essential Eight assessment. Click to open that service. WIRELESS: CHECKS INCLUDE WPA2 and WPA3-Enterprise configuration Certificate validation on client devices Rogue and evil-twin exposure Guest isolation and captive portal bypass IDENTITY: NOT IN SCOPE HERE Covered by internal network penetration testing. Click to open that service. CROWN JEWELS: NOT IN SCOPE HERE Covered by internal network penetration testing. Click to open that service. SERVERS: NOT IN SCOPE HERE Covered by configuration review and benchmarking. Click to open that service.

We test your wireless networks from the position of an attacker in range, covering configuration, isolation and the paths from the air into your network.

  • WPA2 and WPA3-Enterprise configuration and the authentication protocols in use
  • Certificate validation on client devices, and whether an evil-twin network can harvest credentials
  • Pre-shared key strength on WPA2-Personal networks
  • Rogue and evil-twin access point exposure, and how clients respond to them
  • Guest network isolation from the corporate network and from other guests
  • Captive portal security and bypass
  • Segmentation between the wireless and wired networks
  • A survey of how far your networks reach beyond your premises

How we test it

Wi-Fi is the one part of your network an attacker can reach without touching a cable or a public IP address. Signal leaks into car parks, foyers and neighbouring tenancies, and from there someone in range can attempt to join the network, impersonate it, or listen to it. Aurian’s wireless penetration testing is performed by a senior consultant who holds the OffSec Wireless Professional certification, following the Penetration Testing Execution Standard and NIST SP 800-153, from within range of the networks under test.

We begin with a survey: mapping the networks your buildings broadcast, the authentication each one uses, and how far the signal carries beyond your walls. Enterprise Wi-Fi usually depends on client devices validating the network’s certificate before they hand over credentials, and that single setting is the one most often missed. Where it is missing, a consultant can stand up a look-alike network and collect domain credentials from staff devices as they connect, with no action required from the user.

We test guest isolation by trying to cross from the guest network to the corporate one and from one guest to another, we test captive portals for bypass, and we test whether a foothold on the wireless network reaches the wired side. Findings are reported with the physical context that makes them real, where the attacker would stand and what they would reach, and we retest the findings rated high or above once you have remediated.

Standards PTES, NIST SP 800-153, NIST SP 800-115

  1. 01 Survey

    We map the wireless networks in range and how far each one reaches beyond your walls, from the car park to neighbouring tenancies.

  2. 02 Analysis

    We identify the authentication in use on each network and how client devices are configured to trust it.

  3. 03 Attack simulation

    We stand up rogue and evil-twin networks, test credential harvesting and guest isolation, and attempt to cross from the air to the wired network.

  4. 04 Reporting and retest

    You receive findings ranked by severity with the site context. Once you have remediated, a retest of the findings rated high or above confirms what is closed and the report is updated. Retesting is quoted with the test or booked afterwards.

What you receive

Every finding in an Aurian report looks like this: what we found, the evidence, what it means for you, and what to change.

High AUR-2026-014 Sample finding, fictional environment

Corporate Wi-Fi clients accept an evil-twin and surrender credentials

Affected asset
CORP-SECURE WPA2-Enterprise SSID at the head office
Rating
High Likely 4 × High 4 = 16

Description

Managed laptops do not validate the RADIUS server certificate before sending credentials. A consultant standing up a network with the same name captured domain credentials as devices connected automatically, without any user action.

Evidence

[*] Rogue AP 'CORP-SECURE' up on channel 6
[+] EAP identity: CORP\a.nguyen
[+] Captured MSCHAPv2 challenge/response
[+] Cracked: CORP\a.nguyen : Spring2026!
# device connected with no certificate warning

A laptop connected to a look-alike network and its domain credentials were captured and cracked offline.

Impact

An attacker in the car park can collect domain credentials from staff devices as they arrive each morning, then use them against the VPN, Microsoft 365 or the internal network. Because the devices trust any server presenting the right name, no user has to be tricked into anything.

Remediation

Configure client devices to validate the RADIUS server certificate and to trust only your named servers, enforced through group policy or your device management platform. Move towards WPA3-Enterprise, and monitor for rogue access points broadcasting your network names.

References

  • NIST SP 800-153, guidelines for securing wireless local area networks
  • ASD, secure your Wi-Fi network
  • Executive summary written for the board and the insurer, in plain language
  • Technical findings ranked by severity, each with evidence and a fix
  • A signal survey showing where your networks reach beyond your premises
  • Remediation guidance your own engineers can apply without calling us

Common findings

What this kind of engagement typically surfaces, so you can recognise your own environment.

  • Missing certificate validation on clients

    Devices that connect to any network with the right name, so an evil-twin can harvest enterprise credentials without alerting the user.

  • Weak pre-shared keys

    WPA2-Personal networks with guessable or long-shared passphrases that leak to former staff and contractors.

  • Poor guest isolation

    Guest networks that can reach the corporate network, or where one guest can reach another.

  • Rogue access points

    Unmanaged access points added by staff, and the absence of any monitoring that would detect an attacker's.

  • Captive portal bypass

    Guest portals that can be skipped, giving unauthenticated access to whatever the guest network can reach.

  • Signal leakage

    Coverage that extends well beyond the building, widening the area from which an attacker can work unobserved.

Frequently asked questions

We have several locations. Do you test them all?

We agree the locations and the timing at scoping. For organisations with many sites, a representative sample or a rolling programme usually gives the clearest picture for the budget, and the report says which locations were covered.

Will it disrupt our staff or guests?

We design the test to avoid disruption. Techniques that could knock devices off the network are only used with your agreement and, where possible, out of hours. We coordinate with your team throughout.

We only have a guest Wi-Fi. Is it still worth testing?

Yes. The main risk with a guest network is that it reaches somewhere it should not, or becomes a foothold onto the corporate network. Testing confirms the isolation holds.

Are your consultants qualified in wireless testing specifically?

Yes. Aurian's consultants hold the OffSec Wireless Professional certification, which is examined by attacking live wireless networks, so the people testing your Wi-Fi have been examined in exactly this work.

How long does it take?

It depends on the number of sites and networks: typically one to three days of testing per site, with the report following. We confirm the timeframe after scoping.

Related services

Internal network penetration testing

Internal penetration testing from a foothold on your network: Active Directory attack paths, credential hygiene and segmentation, tested to domain admin.

Configuration review and benchmarking

Security configuration review of firewalls, servers, endpoints, network devices and Microsoft 365 against CIS Benchmarks, with the exact settings to change.

Social engineering and phishing simulation

Phishing simulation and social engineering assessment: measured, consented email and voice campaigns that show your awareness baseline and process gaps.

Penetration testing services

Scope a test with a senior consultant

Tell us what you need to know about your environment. We reply within one business day.

Scope a test Call 1300 AURIAN

Aurian Security is an Australian penetration testing and security assurance firm. Senior consultants perform every engagement, for clients across the country.

Penetration testing

  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation

Assurance and managed

  • Security assurance
  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
  • Managed security
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring

Company

  • About Aurian
  • How we work
  • Industries
  • Blog
  • Contact
  • Privacy policy
526/368 Sussex St, Sydney NSW 2000 1300 AURIAN (1300 287 426) sales@aurian.com.au

© 2026 Aurian Security Pty Ltd. ACN 639 930 528.

This site is static, loads no third-party trackers, and publishes a security.txt.