Wireless Penetration Testing in India & UAE.
On-site wireless penetration testing across corporate, guest, IoT, BYOD and Bluetooth attack surfaces. We test WPA2/WPA3-Enterprise authentication, rogue AP scenarios, evil-twin attacks, client-side credential capture and post-association lateral movement into the wired network.
What is wireless penetration testing?
Wireless penetration testing assesses your Wi-Fi networks for weak encryption, rogue access points, and guest-to-corporate bridging that let an attacker onto your internal network from the car park. Macksofy tests WPA2/WPA3, segmentation, and NAC controls, delivering a CERT-In-format report for offices across India.
Your perimeter is not your wall.
Wireless is the attack surface most internal pentests skip, because it cannot be tested from a VPN. Someone has to walk the floors with a directional antenna and then sit in the car park.
- Surface the unauthorised AP in the boardroom that nobody admits installing
- Validate that the guest WiFi actually segments from corporate (and not just on paper)
- Identify weak PSK / EAP credentials before an attacker in the car-park does
- Satisfy CERT-In annual VAPT and PCI-DSS req 11.1 wireless scanning requirements
Employee-installed AP bridging to the wired finance VLAN — not in any inventory
Corporate SSID is comfortably readable here. This is where the evil-twin runs from, and where a captured certificate would have reached the VPN.
- ▸Floor-by-floor coverage and risk heat map
- ▸Rogue AP inventory, employee- and attacker-installed
- ▸Per-SSID authentication and segmentation findings
- ▸Wired-side blast radius from each cracked SSID
- ▸Bluetooth / BLE surface, where scoped
Four radio surfaces, one site visit.
WPA2-PSK, WPA3-SAE and 802.1X-Enterprise authentication, plus whether guest genuinely segments from corporate or merely says it does.
The AV bridge in the boardroom, the range extender under someone's desk, and anything an attacker has left behind. Found by walking the floors, not by asking.
Conference bridges, ID badges, smart locks and IoT beacons. Adds one to two days per site and is worth it wherever physical access matters.
Building management, plant sensors and connected medical devices — usually on the oldest crypto in the building and the least-watched VLAN.
WPA3 closes some doors. It does not close the client.
Upgrading the encryption does not fix a supplicant that will happily authenticate to a rogue RADIUS server, or a laptop that auto-connects to any SSID it has ever seen. Here is what applies to what.
| Technique | WPA2-PSK | WPA3-SAE | 802.1X EAP | Open guest | IoT / BMS |
|---|---|---|---|---|---|
4-way handshake capture → offline crack WPA2 | |||||
SAE / Dragonblood-class downgrade & side-channel WPA3 | ~ | ~ | |||
WPS Pixie-Dust WPA2 | ~ | ~ | |||
Rogue RADIUS credential capture (hostapd-wpe) 802.1X | ~ | ||||
Certificate-validation bypass on the supplicant 802.1X | ~ | ||||
Evil-twin AP impersonation Client | ~ | ||||
Karma-style auto-connect abuse Client | ~ | ~ | |||
Captive-portal credential phishing Client | |||||
Post-association pivot to wired VLANs Lateral |
Note the bottom row. Whichever SSID gives way, the finding that matters is what it reaches on the wired side — which is why segmentation validation is part of every wireless engagement rather than a separate quote.
Six phases, from survey to pivot.
- ▸RF survey of corporate + guest + IoT SSIDs across all floors
- ▸Rogue AP discovery (employee-installed, attacker-installed)
- ▸Client device profiling (who is connecting where)
- ▸Bluetooth / BLE beacon enumeration
- ▸EAPOL / 4-way handshake capture
- ▸Offline cracking (Hashcat, John, custom wordlists)
- ▸WPA3 SAE attack scenarios (Dragonblood-class)
- ▸WPS Pixie-Dust where enabled
- ▸EAP method enumeration (PEAP, EAP-TTLS, EAP-TLS)
- ▸Certificate validation bypass testing (EAP-PWN-style)
- ▸Rogue RADIUS attack (hostapd-wpe) for credential capture
- ▸Privilege analysis post-authentication
- ▸Evil-twin AP impersonation
- ▸Karma-style auto-connect exploitation
- ▸Captive-portal credential phishing (with RoE consent)
- ▸Roaming behaviour analysis
- ▸Once on the WiFi, attempt lateral movement into wired VLANs
- ▸Guest → corporate segmentation validation
- ▸IoT VLAN → corporate VLAN reachability
- ▸Site-by-site report with floor-plan heat maps
- ▸Per-finding remediation (RADIUS hardening, certificate pinning, segmentation)
- ▸Free retest within 30 days
Both found before anyone else did.
Scope · 12-floor corporate HQ, all SSIDs + Bluetooth
Finding · Evil-twin rogue AP impersonating corporate SSID captured 8 employee credentials; 1 captured certificate would have enabled VPN access from the car-park
Critical — pre-incident discovery; certificate revoked + RADIUS hardened
Scope · Patient-care WiFi + IoT medical-device WiFi
Finding · IoT VLAN allowed lateral movement to HMIS web interface via unfiltered IPv6 neighbour discovery
High — segmentation rule added; HIPAA-aligned exposure closed
We bring the kit to your floor.
Operators travel with directional antennas, SDR and the full survey rig. Multi-site estates are sequenced so the report lands as one document with per-site heat maps, not as several disconnected PDFs.
Sites outside these cities are quoted with travel included — say where the buildings are and the proposal covers all of them.
Survey, capture, crack, impersonate.
The 2.4, 5 and 6 GHz noise floor is surveyed with Kismet before anything active runs, so rogue APs are found against a known baseline rather than guessed at.
Transparent tiers. No surprises at quote time.
Indicative price ranges based on typical Indian engagements. Final fixed-price quote within 72 hours of the discovery call.
Focused
- Manual + tooled testing
- CERT-In format report
- Free 30-day retest
Stack
- Everything in Focused
- Web + API + mobile coverage
- Executive + technical briefings
Programme
- Everything in Stack
- Quarterly cycles + post-release retests
- Same consultants throughout
Note · Indicative pricing in INR. Final quote depends on scope, asset count and engagement window. Fixed-price proposal within 72 hours.
What you get per site
- Site-by-site wireless coverage + risk heat map
- Rogue AP inventory (employee + attacker-installed)
- Per-SSID finding writeups (authentication weakness, segmentation, EAP)
- Wired-side blast-radius assessment from each cracked SSID
- Hardening recommendations: RADIUS, certificate pinning, segmentation, IDS
- Free retest within 30 days of fix submission
- PCI-DSS req 11.1 evidence pack (if in scope)
Sectors we operate in
Empanelled by CERT-In. Accredited by EC-Council.
“We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.”
“The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.”
“Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.”
Questions before we book travel.
Where Macksofy delivers Wireless Pentest.
On-site engagements across India's BFSI, fintech, government and SaaS metros plus the UAE. Senior consultants fly from Mumbai BKC for kickoff, key reviews and exit briefings; remote weeks run through the rest of the engagement.
Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.
Get a fixed-price proposal in 48 hours.
Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.
- CERT-In Empanelled
- EC-Council ATC · CompTIA Authorized
- Thousands of professionals trained
- India + UAE engagements
