Skip to content
Macksofy Technologies
WPA2 / WPA3 · 802.1X · Guest · IoT · Bluetooth

Wireless Penetration Testing in India & UAE.

On-site wireless penetration testing across corporate, guest, IoT, BYOD and Bluetooth attack surfaces. We test WPA2/WPA3-Enterprise authentication, rogue AP scenarios, evil-twin attacks, client-side credential capture and post-association lateral movement into the wired network.

On-site
physical-layer testing
9 cities
India + UAE
11.1
PCI-DSS evidence
30 days
free retest window
In short

What is wireless penetration testing?

Wireless penetration testing assesses your Wi-Fi networks for weak encryption, rogue access points, and guest-to-corporate bridging that let an attacker onto your internal network from the car park. Macksofy tests WPA2/WPA3, segmentation, and NAC controls, delivering a CERT-In-format report for offices across India.

Why on-site

Your perimeter is not your wall.

Wireless is the attack surface most internal pentests skip, because it cannot be tested from a VPN. Someone has to walk the floors with a directional antenna and then sit in the car park.

  • Surface the unauthorised AP in the boardroom that nobody admits installing
  • Validate that the guest WiFi actually segments from corporate (and not just on paper)
  • Identify weak PSK / EAP credentials before an attacker in the car-park does
  • Satisfy CERT-In annual VAPT and PCI-DSS req 11.1 wireless scanning requirements
Site cross-section · where the signal actually goes
CORP-SECGUESTIOT-BMSAV-BRIDGE
Floor 12 · Executive
CORP-SECGUEST
Floor 8 · Finance
CORP-SECGUEST
Floor 5 · Boardroom
CORP-SECGUESTAV-BRIDGE

Employee-installed AP bridging to the wired finance VLAN — not in any inventory

Floor 2 · Operations
CORP-SECGUESTIOT-BMS
Ground · Reception
GUEST
Car park, 40 m from reception

Corporate SSID is comfortably readable here. This is where the evil-twin runs from, and where a captured certificate would have reached the VPN.

The survey produces
  • Floor-by-floor coverage and risk heat map
  • Rogue AP inventory, employee- and attacker-installed
  • Per-SSID authentication and segmentation findings
  • Wired-side blast radius from each cracked SSID
  • Bluetooth / BLE surface, where scoped
Deauth and evil-twin tests are scheduled outside business hours. Passive survey and offline cracking have zero impact.
What is in scope

Four radio surfaces, one site visit.

Corporate & guest SSIDs

WPA2-PSK, WPA3-SAE and 802.1X-Enterprise authentication, plus whether guest genuinely segments from corporate or merely says it does.

Rogue & shadow APs

The AV bridge in the boardroom, the range extender under someone's desk, and anything an attacker has left behind. Found by walking the floors, not by asking.

Bluetooth & BLE

Conference bridges, ID badges, smart locks and IoT beacons. Adds one to two days per site and is worth it wherever physical access matters.

IoT, BMS and medical

Building management, plant sensors and connected medical devices — usually on the oldest crypto in the building and the least-watched VLAN.

Technique coverage

WPA3 closes some doors. It does not close the client.

Upgrading the encryption does not fix a supplicant that will happily authenticate to a rogue RADIUS server, or a laptop that auto-connects to any SSID it has ever seen. Here is what applies to what.

Technique applicability by SSID type
TechniqueWPA2-PSKWPA3-SAE802.1X EAPOpen guestIoT / BMS
4-way handshake capture → offline crack
WPA2
SAE / Dragonblood-class downgrade & side-channel
WPA3
~
~
WPS Pixie-Dust
WPA2
~
~
Rogue RADIUS credential capture (hostapd-wpe)
802.1X
~
Certificate-validation bypass on the supplicant
802.1X
~
Evil-twin AP impersonation
Client
~
Karma-style auto-connect abuse
Client
~
~
Captive-portal credential phishing
Client
Post-association pivot to wired VLANs
Lateral
in scope depends on configuration not applicable

Note the bottom row. Whichever SSID gives way, the finding that matters is what it reaches on the wired side — which is why segmentation validation is part of every wireless engagement rather than a separate quote.

Methodology

Six phases, from survey to pivot.

Phase 1
Site survey & passive recon
  • RF survey of corporate + guest + IoT SSIDs across all floors
  • Rogue AP discovery (employee-installed, attacker-installed)
  • Client device profiling (who is connecting where)
  • Bluetooth / BLE beacon enumeration
Phase 2
WPA2 / WPA3 attack
  • EAPOL / 4-way handshake capture
  • Offline cracking (Hashcat, John, custom wordlists)
  • WPA3 SAE attack scenarios (Dragonblood-class)
  • WPS Pixie-Dust where enabled
Phase 3
802.1X / EAP attack
  • EAP method enumeration (PEAP, EAP-TTLS, EAP-TLS)
  • Certificate validation bypass testing (EAP-PWN-style)
  • Rogue RADIUS attack (hostapd-wpe) for credential capture
  • Privilege analysis post-authentication
Phase 4
Evil-twin & client attacks
  • Evil-twin AP impersonation
  • Karma-style auto-connect exploitation
  • Captive-portal credential phishing (with RoE consent)
  • Roaming behaviour analysis
Phase 5
Post-association lateral movement
  • Once on the WiFi, attempt lateral movement into wired VLANs
  • Guest → corporate segmentation validation
  • IoT VLAN → corporate VLAN reachability
Phase 6
Reporting & retest
  • Site-by-site report with floor-plan heat maps
  • Per-finding remediation (RADIUS hardening, certificate pinning, segmentation)
  • Free retest within 30 days
Engagement snapshots

Both found before anyone else did.

BFSI (Mumbai BKC)

Scope · 12-floor corporate HQ, all SSIDs + Bluetooth

Finding · Evil-twin rogue AP impersonating corporate SSID captured 8 employee credentials; 1 captured certificate would have enabled VPN access from the car-park

Critical — pre-incident discovery; certificate revoked + RADIUS hardened

Risk severity · Critical
LMHC
Hospital Group (Bengaluru)

Scope · Patient-care WiFi + IoT medical-device WiFi

Finding · IoT VLAN allowed lateral movement to HMIS web interface via unfiltered IPv6 neighbour discovery

High — segmentation rule added; HIPAA-aligned exposure closed

Risk severity · High
LMHC
Logistics

We bring the kit to your floor.

Operators travel with directional antennas, SDR and the full survey rig. Multi-site estates are sequenced so the report lands as one document with per-site heat maps, not as several disconnected PDFs.

Disruptive tests scheduled with your IT team outside business hours.
Remote-assisted scope is possible with a trusted local operator, but most of the value is on site.
Operators travel to
MumbaiDelhi NCRBengaluruHyderabadChennaiPuneAhmedabadDubaiAbu Dhabi

Sites outside these cities are quoted with travel included — say where the buildings are and the proposal covers all of them.

Kit

Survey, capture, crack, impersonate.

The 2.4, 5 and 6 GHz noise floor is surveyed with Kismet before anything active runs, so rogue APs are found against a known baseline rather than guessed at.

Tools we operate
Aircrack-ng suiteBettercaphostapd-wpe / hostapd-manaEAPHammerWiFi PineappleKismetWireshark + tsharkHashcatBluetooth: bettercap-ble · gattool · btscannerSoftware-Defined Radio (SDR) for Sub-GHz
Indicative pricing · INR

Transparent tiers. No surprises at quote time.

Indicative price ranges based on typical Indian engagements. Final fixed-price quote within 72 hours of the discovery call.

Free 30-day retest · CERT-In format reports
Tier 01

Focused

₹2.5L–₹5L
Single asset or app
  • Manual + tooled testing
  • CERT-In format report
  • Free 30-day retest
Request a fixed-price quote
Tier 02

Stack

₹6L–₹12L
Multi-asset engagement
  • Everything in Focused
  • Web + API + mobile coverage
  • Executive + technical briefings
Request a fixed-price quote
Tier 03

Programme

Starts at ₹15L
Quarterly retainer · large estate
  • Everything in Stack
  • Quarterly cycles + post-release retests
  • Same consultants throughout
Request a fixed-price quote

Note · Indicative pricing in INR. Final quote depends on scope, asset count and engagement window. Fixed-price proposal within 72 hours.

Deliverables

What you get per site

  • Site-by-site wireless coverage + risk heat map
  • Rogue AP inventory (employee + attacker-installed)
  • Per-SSID finding writeups (authentication weakness, segmentation, EAP)
  • Wired-side blast-radius assessment from each cracked SSID
  • Hardening recommendations: RADIUS, certificate pinning, segmentation, IDS
  • Free retest within 30 days of fix submission
  • PCI-DSS req 11.1 evidence pack (if in scope)
Industries

Sectors we operate in

Banking & Financial ServicesInsurance & InsurTechGovernment & PSUHealthcare & HealthTechManufacturing & EnergyRetail & E-commerceHospitalitySaaS & Product Companies
What clients say · Trusted India + UAE

Empanelled by CERT-In. Accredited by EC-Council.

CERT-In Empanelled
Govt of India · MeitY
EC-Council ATC
Authorized Training
ISO 27001 Certified
Info Security Mgmt
CompTIA Authorized Partner
Training Delivery
We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.
LF
Information Security Manager
Listed Fintech · BKC, Mumbai
The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.
MP
Cyber Cell
Maharashtra Police · Mumbai
Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.
HS
DevSecOps Lead
Healthcare SaaS · Hyderabad
FAQ

Questions before we book travel.

Yes — wireless testing is fundamentally a physical-layer activity. Macksofy operators travel to your site (Mumbai · Delhi NCR · Bengaluru · Hyderabad · Chennai · Pune · Ahmedabad · Dubai · Abu Dhabi) with kit. Remote-assisted scope is possible if you have a trusted local operator, but the bulk of value comes from on-site.
Active attacks (deauth, evil-twin) can briefly affect connectivity in the targeted area; we coordinate with your IT team to schedule disruptive tests outside business hours. Passive recon and offline cracking are zero-impact.
Optional — Bluetooth assessment adds 1–2 days per site but surfaces a real attack surface (conference bridges, ID badges, IoT, smart locks). Recommended for sensitive sites; optional for general corporate.
Delivery footprint

Where Macksofy delivers Wireless Pentest.

On-site engagements across India's BFSI, fintech, government and SaaS metros plus the UAE. Senior consultants fly from Mumbai BKC for kickoff, key reviews and exit briefings; remote weeks run through the rest of the engagement.

References & standards

Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.

Talk to us

Get a fixed-price proposal in 48 hours.

Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.

CERT-In Empanelled
Information Security Auditor · India
  • CERT-In Empanelled
  • EC-Council ATC · CompTIA Authorized
  • Thousands of professionals trained
  • India + UAE engagements