Strategy & Governance

Managed Security

Cyber Defense

Governance, Risk & Compliance

Operations & People

Talk to us

Cyber Defense

Wireless security testing, from the car park.

Wireless security testing services exist because your network has an edge you cannot see. Every access point radiates past the walls, and the attacker who uses it never signs the visitor book. The question is not whether your Wi-Fi has a password; it is what someone within radio range can reach without one.

We test from where an attacker would actually sit (outside the building, in the lobby, in the shared floor above) and then from the inside as a guest and as an employee. That covers the authentication itself, what the guest network can see, whether an access point announcing your network name is really yours, and how much of your estate is one associated device away.

The scope extends past Wi-Fi. Bluetooth and Bluetooth Low Energy peripherals, wireless keyboards and presentation clickers, badge readers, and the proprietary radio links in building systems are all part of the perimeter and are almost never tested. Where those devices are industrial, the work continues into OT and IoT security.

Why you need it

01 / 06

Why wireless is tested separately.

01

Radio does not respect the building line.

Physical access control assumes an attacker has to get in. A directional antenna in the car park removes that assumption, and no amount of door hardware helps. Coverage bleed is measurable and almost always larger than the facilities drawing suggests.

02

An access point is trivial to impersonate.

Devices remember networks and reconnect to a familiar name automatically. A rogue access point announcing that name, or a captive portal that looks like yours, collects credentials from people doing nothing wrong. Detecting this requires wireless monitoring most estates do not have.

03

Guest networks leak more than you think.

The guest SSID is meant to reach the internet and nothing else. In practice we find it sharing a VLAN with printers, reaching the management interfaces of the access points themselves, or resolving internal DNS, which is enough to map the estate before anyone authenticates.

04

Enterprise Wi-Fi is misconfigured more often than it is broken.

WPA2 and WPA3 Enterprise are strong when the client validates the server certificate. When validation is not enforced by policy, an attacker stands up a lookalike authentication server and collects domain credentials from every laptop that walks past.

Instrument

02 / 06

What a wireless scan reports, and what a test proves.

The same site survey, twice: the automated list of networks and weaknesses, and the two findings that combine into a credential.

What we deliver

03 / 06

What the assessment covers.

01

Site survey and coverage mapping

Every network broadcasting in and around your premises, their encryption and authentication configuration, signal reach beyond the building envelope, and the networks present that you do not own, including a neighbour's access point your devices have been associating with.

02

Authentication testing

WPA2 and WPA3 Personal against captured handshakes and realistic password policy, and Enterprise deployments against the failure that matters: whether clients validate the RADIUS server certificate, and what an evil-twin authentication server harvests when they do not.

03

Rogue and evil-twin detection

Unauthorised access points on your wired network, devices impersonating your network name, and (with authorisation, in a controlled window) a rogue of our own, to measure whether your wireless infrastructure or your users notice.

04

Segmentation and guest isolation

From an associated guest device: what is reachable, what resolves, whether client isolation is enforced between guests, and whether the access point and controller management interfaces are exposed to the network they serve. Then the same from an employee device.

05

Bluetooth, BLE and peripheral testing

Discoverable devices, pairing and bonding weaknesses, unauthenticated BLE characteristics that expose data or accept writes, and wireless input peripherals vulnerable to injection or eavesdropping.

06

Wireless policy and monitoring review

Client configuration and certificate validation policy on managed devices, pre-shared key rotation and who knows the current one, onboarding for personal devices, and whether anything in your estate would generate an alert when a rogue appears.

How we run it

04 / 06

Five steps, on site.

  1. 01

    Scoping and site agreement

    Locations, networks and device classes in scope, testing windows, and written permission from whoever controls the premises, essential in shared or leased buildings, where neighbouring networks are explicitly out of bounds.

    Week 0
  2. 02

    Passive survey

    Listening only. Networks, clients, encryption, coverage and signal reach from inside and from realistic external positions. Nothing is transmitted, and this alone frequently identifies a network nobody meant to be broadcasting.

    Day 1
  3. 03

    Authentication and rogue testing

    Handshake capture and offline analysis, Enterprise certificate-validation testing, and, where authorised, a controlled rogue access point in an agreed window, aimed at named test devices rather than at your staff at large.

    Days 2-3
  4. 04

    Post-association testing

    Associated as a guest, then as an employee: segmentation, isolation, reachable services, management interface exposure, and the route from a wireless client to anything that matters.

    Days 3-4
  5. 05

    Reporting and re-test

    Findings with location, access point and evidence, ranked by what they reach, with configuration-level fixes for your wireless controller. Re-tested after remediation.

    Day 5, then after fixes

Key benefits

05 / 06

What changes after.

You know how far your network reaches

Measured coverage beyond the building, with the access points and power settings responsible, a finding you can act on the same week.

Guest means guest

Isolation and segmentation verified from an associated device rather than assumed from the controller configuration, with the reachable services enumerated and closed.

Credential theft over the air is closed off

Certificate validation enforced on managed clients, so an evil twin collects nothing worth having even when it works perfectly.

Tools we use

06 / 06

Named, and used on your engagement.

No “latest tech tools”. These are the ones your report will cite, alongside the manual work that a tool cannot do for you.

Survey and capture

  • Kismet
  • Aircrack-ng suite
  • Wireshark
  • Ekahau-style coverage mapping

Authentication testing

  • hostapd-wpe
  • EAPHammer
  • hcxtools
  • Hashcat

Radio and peripherals

  • HackRF
  • Ubertooth
  • Flipper Zero
  • Proxmark3
  • bettercap

Post-association

  • Nmap
  • Responder
  • Burp Suite Professional

Methodology

  • OWASP Testing Guide
  • PTES
  • NIST SP 800-153

Why Aphelion

Shared

Four things you can check.

01

The work is done by people with names.

Darshap Nayak, formerly of KPMG, holds a master’s degree in cybersecurity and more than seven years in security operations. Jaimin Somani brings fifteen-plus years of academic and hands-on VAPT. Hemang Desai is an ICT network specialist from Australia. You will meet them, not a logo.

Meet the team
02

Evidence, not adjectives.

Every finding arrives with the reproduction steps, the affected asset and the fix, ranked by what it actually reaches in your environment, not by a CVSS number copied from a scanner. You get the report and the raw output, not a summary of a summary.

See how we test
03

Two offices, one practice.

Ahmedabad and Sharjah, working the same methodology on the same tooling. Indian data-residency requirements and UAE delivery are both ordinary here, and the AphelioNYX AD Pen-Test module runs entirely inside your perimeter when regulation says it must.

The platform
04

What we will not do.

Invent a statistic to make a slide land. Publish your name as a client without written permission. Print an award badge nobody awarded. Founded in 2024. We say so, and we attribute experience to the people who have it.

Ask us anything

100+ organizations secured

Across the globe, and across eight industries. We name a client only with their written permission.

  • Finance & Banking
  • Healthcare
  • Retail & E-commerce
  • Technology
  • SaaS
  • Hospitality
  • Manufacturing
  • Pharmaceuticals

AphelioNYX is SOC 2, ISO and GDPR compliant; attestations are available on request under NDA. We would rather hand you the report than print a badge.

Questions

FAQ

What clients ask before a wireless test.

Do you have to be on our premises?
Yes. Radio testing needs radio range, so this is an on-site engagement with a tester and a kit of antennas and software-defined radios. We test from external positions first (the car park, the street, the floor above) because that is where an attacker sits, and then from inside as a guest and as an employee.
We are in a shared office building. Can you still test?
Yes, with tighter rules. We need written permission from the building or landlord as well as from you, and neighbouring networks are strictly out of scope. We identify them so that you know what your devices can see, and we do not touch them. Shared buildings usually produce the most interesting coverage and rogue findings for exactly this reason.
Will testing knock our users off the network?
Some classic wireless techniques rely on deauthentication, which does disconnect clients briefly. We avoid them by default, capture handshakes passively where we can, and confine any technique that disrupts service to an agreed window against named test devices. If you need zero disruption during business hours, say so at scoping and we plan around it.
We use WPA3. Are we finished?
WPA3 removes several real weaknesses and is worth deploying, but most estates run it in transition mode alongside WPA2 for older clients, which preserves the older attack surface. And the findings that matter most in Enterprise deployments (certificate validation, guest segmentation, management interface exposure, rogue detection) are configuration and architecture issues that WPA3 does not address at all.
Does this cover Bluetooth and our badge readers?
It can, and it should be named in scope explicitly because it changes the kit we bring. Bluetooth and BLE peripherals, wireless input devices, and contactless badge systems are all assessable, and are frequently the least examined part of a physical estate. Industrial radio and building-management protocols are better handled as an OT and IoT security assessment.

Forty-five minutes. Your environment, not a slide deck.

A personalised walkthrough and a free readiness assessment against the frameworks you are actually being asked for. Pick a time that suits you, or write to us. We reply within one business day.