Wireless penetration testing

Test whether someone near the site can turn wireless access into a path to systems they should not reach.

Damocles Wireless Penetration Testing assesses approved corporate, guest and operational wireless networks, authentication, encryption, client isolation, segmentation and the access available after connection.

Corporate and guest Wi-FiAuthentication and encryptionClient isolation and segmentationPost-connect testing
Why customers buy this test

Validate wireless as a security boundary.

Wireless security depends on more than encryption. A network can use modern wireless security and still expose weak onboarding, shared credentials, unsafe guest access, poor client isolation or unintended paths from wireless networks into internal systems.

Damocles assesses the authorised wireless environment and, where in scope, tests what access becomes available after connection so the customer can understand the real consequence of a compromised or unauthorised wireless client.

01

Validate wireless access control

Assess authentication, credential use and onboarding paths that determine who can join the network.

02

Validate isolation

Test client-to-client and wireless-to-internal segmentation against the intended design.

03

Assess post-connect exposure

Determine what services and systems an authorised or compromised wireless client can reach.

What we test

Approved wireless networks, security modes, clients and connected network paths.

Testing is coordinated around site access, radio coverage, authorised SSIDs, client devices and the agreed production-safety constraints.

AP

Access points and SSIDs

Approved corporate, guest and operational wireless networks and their broadcast/configuration behaviour.

AU

Authentication

Enterprise or personal authentication, certificates, credentials, onboarding and reauthentication behaviour.

EN

Encryption

Wireless security modes and downgrade or weak-configuration conditions where applicable.

CI

Client isolation

Access between wireless clients and protections intended to prevent peer-to-peer attack paths.

SG

Network segmentation

Wireless access into user, server, management, guest or restricted networks.

PC

Post-connect access

Services, identity paths and management interfaces reachable after approved connection.

Technical assurance

Validate the security boundary around wireless access.

Test corporate, guest and representative wireless networks to identify weak authentication, isolation, management and trust paths into connected environments.

Network discovery

Authorised wireless networks, broadcast behaviour and unexpected exposure.

Authentication

Enterprise, personal and captive-portal access controls.

Client isolation

Whether connected devices can reach each other unexpectedly.

Network separation

Boundaries between guest, corporate and sensitive environments.

Management security

Administrative interfaces and wireless infrastructure controls.

Rogue access risks

Client trust and resistance to misleading or unauthorised access points.

Encryption and legacy modes

Protocol choices that weaken confidentiality or access control.

12governed test areas
3authorised testing perspectives
6controlled evidence outputs
1framework / control evidence mappings
What we actually test

Representative technical coverage with the evidence produced.

These are governed procedures from the service assurance profile—not generic marketing categories. The complete matrix below records applicability, access requirements and limitations for every coverage area.

Jump to full coverage matrix ↓
Coverage area

Approved SSIDs and locations

Damocles surveys each approved site and location for SSIDs, BSSIDs, channels, signal presence and advertised security and reconciles results with the authorised inventory.

Evidence producedA discovered-item register with address, service, version or location and reconciliation status.
Framework references
Technical Guide to Information Security Testing and Assessment SP 800-115
Coverage area

Authentication modes

Damocles validates applicable WPA2, WPA3, enterprise or personal authentication modes using supplied test clients and identities.

Evidence producedEvidence records the SSID, BSSID, radio, authentication, client-isolation or post-connect result relevant to authentication modes.
Framework references
Technical Guide to Information Security Testing and Assessment SP 800-115
Coverage area

Certificate and credential onboarding

Damocles follows certificate and credential enrolment, renewal, storage and removal on an approved client and reviews the associated identity policy.

Evidence producedEvidence records the SSID, BSSID, radio, authentication, client-isolation or post-connect result relevant to certificate and credential onboarding.
Framework references
Technical Guide to Information Security Testing and Assessment SP 800-115
Coverage area

Encryption configuration

Damocles inspects negotiated encryption, protected-management settings and controller policy and performs only authorised downgrade checks.

Evidence producedConfiguration excerpts, object or rule identifiers and observed validation results.
Framework references
Technical Guide to Information Security Testing and Assessment SP 800-115
Coverage area

Client isolation

Damocles attempts direct client-to-client communication between supplied clients on the same approved SSID.

Evidence producedEvidence records the SSID, BSSID, radio, authentication, client-isolation or post-connect result relevant to client isolation.
Framework references
Technical Guide to Information Security Testing and Assessment SP 800-115
Coverage area

Guest isolation

Damocles attempts approved guest-to-corporate, guest-to-management and guest-to-peer paths after connection.

Evidence producedEvidence records the SSID, BSSID, radio, authentication, client-isolation or post-connect result relevant to guest isolation.
Framework references
Technical Guide to Information Security Testing and Assessment SP 800-115

Showing 6 representative areas. The full governed matrix contains 12 coverage areas.

Standards and assurance coverage

See how this engagement is structured, classified and mapped before opening the full evidence matrix.

References are shown according to the role they play in the engagement. Methodologies guide testing, taxonomies classify findings, severity methods support consistent scoring, and control mappings connect scoped evidence to broader assurance work.

01 · Test method

How testing is structured

Approved methodology, verification and testing guidance used to select and structure relevant procedures within the authorised scope.

Technical Guide to Information Security Testing and Assessment SP 800-115
02 · Finding language

How weaknesses and severity are classified

Approved risk, weakness and severity references provide a consistent language for confirmed findings without replacing customer-specific business impact.

Common Weakness Enumeration 4.20Common Vulnerability Scoring System 4.0
03 · Control evidence

What maps into compliance and assurance work

1governed evidence mapping across 1 approved framework, with framework-level context where exact controls are not claimed.
1 contextual
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0Contextual
Framework-level context

The engagement produces point-in-time technical evidence about the configured and observed security behaviour within the authorised Wireless penetration testing scope.

Jump to full control mapping ↓
04 · Evidence package

What the customer can use after the engagement

A prioritised report with validated wireless access and trust findings, evidence, remediation guidance and retest results.

  • Authorised scope and rules of engagement
  • Coverage matrix
  • Retest and residual-risk record
  • + 3 additional controlled outputs

What this means: technical evidence may support risk, compliance and audit activity where the mapping is applicable. It does not by itself certify the organisation, establish complete compliance or assess controls outside the authorised scope.

How we test

Manual validation backed by controlled evidence.

Damocles observes authorised radio environments onsite, joins approved SSIDs with supplied clients, and validates isolation and post-connect paths against configuration evidence. Radio observations are location and time bound, and production-impacting deauthentication is excluded unless separately authorised.

How to read the mapping

Evidence is mapped to the part of a control we can actually assess.

Directly assessed means the engagement tests the relevant behaviour. Supporting evidence means the result can contribute to a broader control assessment. Contextual references explain relevance without claiming that the control was tested.

All relevant frameworks
Technical Guide to Information Security Testing and Assessment SP 800-115Information Security Manual June 2026Common Weakness Enumeration 4.20Common Vulnerability Scoring System 4.0Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
Testing perspectives3 authorised viewpoints and access models

Onsite radio and unauthenticated wireless assessor

Surveys approved locations for SSIDs, channels, encryption and authorised lookalike conditions without joining protected networks.

Included when
Used for radio discovery, advertised security and location-specific exposure.
Access required
Site access, approved locations, SSID inventory, testing window and radio constraints.
Limitations
Observations are limited by location, time, equipment and signal propagation.

Supplied corporate or guest wireless client

Joins approved SSIDs with supplied credentials or certificates and tests isolation and post-connect access.

Included when
Used when authenticated corporate or guest behaviour is included.
Access required
A test device, onboarding material, credentials and expected network access.
Limitations
Represents only the supplied client, identity, SSID and location.

Wireless configuration and segmentation reviewer

Reviews controller, access-point, identity and network policy and correlates it with radio and connectivity results.

Included when
Used when wireless configuration and downstream segmentation evidence is available.
Access required
Controller exports, authentication policy, VLAN mapping, certificates and flow expectations.
Limitations
Configuration alone does not prove RF coverage or live enforcement.
Exact test coverage and evidence12 governed coverage areas
What Damocles tests, the evidence produced and the scope boundary for each controlled coverage area.
Coverage areaWhat Damocles testsPerspective and accessEvidence producedReferences and limits
Approved SSIDs and locationsDamocles surveys each approved site and location for SSIDs, BSSIDs, channels, signal presence and advertised security and reconciles results with the authorised inventory.Onsite radio and unauthenticated wireless assessor
Approved ranges, names, locations and the expected asset or interface inventory.
A discovered-item register with address, service, version or location and reconciliation status.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Performed for customer-owned ranges, names, locations or interfaces listed in the authorised inventory.

Limit: Discovery is point-in-time and cannot establish ownership or absence outside the approved inventory; intrusive enumeration stops at the agreed boundary.

Authentication modesDamocles validates applicable WPA2, WPA3, enterprise or personal authentication modes using supplied test clients and identities.Supplied corporate or guest wireless client
Assessment requires approved site access, locations, SSIDs, test clients, onboarding material and controller or network evidence, selected specifically for authentication modes.
Evidence records the SSID, BSSID, radio, authentication, client-isolation or post-connect result relevant to authentication modes.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Authentication modes when the wireless feature is present at an approved location.

Limit: The conclusion is limited to the sampled authentication modes; radio results are location and time bound; disruptive RF actions require separate written authority.

Certificate and credential onboardingDamocles follows certificate and credential enrolment, renewal, storage and removal on an approved client and reviews the associated identity policy.Onsite radio and unauthenticated wireless assessor
Assessment requires approved site access, locations, SSIDs, test clients, onboarding material and controller or network evidence, selected specifically for certificate and credential onboarding.
Evidence records the SSID, BSSID, radio, authentication, client-isolation or post-connect result relevant to certificate and credential onboarding.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Certificate and credential onboarding when the wireless feature is present at an approved location.

Limit: The conclusion is limited to the sampled certificate and credential onboarding; radio results are location and time bound; disruptive RF actions require separate written authority.

Encryption configurationDamocles inspects negotiated encryption, protected-management settings and controller policy and performs only authorised downgrade checks.Wireless configuration and segmentation reviewer
Current configuration export or read-only access, diagrams, owners and representative validation endpoints.
Configuration excerpts, object or rule identifiers and observed validation results.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Performed when current configuration evidence and a representative endpoint or device are included in the review.

Limit: A configuration snapshot cannot prove continuous enforcement across excluded nodes; validation avoids changes unless implementation work is authorised.

Client isolationDamocles attempts direct client-to-client communication between supplied clients on the same approved SSID.Onsite radio and unauthenticated wireless assessor
Assessment requires approved site access, locations, SSIDs, test clients, onboarding material and controller or network evidence, selected specifically for client isolation.
Evidence records the SSID, BSSID, radio, authentication, client-isolation or post-connect result relevant to client isolation.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Client isolation when the wireless feature is present at an approved location.

Limit: The conclusion is limited to the sampled client isolation; radio results are location and time bound; disruptive RF actions require separate written authority.

Guest isolationDamocles attempts approved guest-to-corporate, guest-to-management and guest-to-peer paths after connection.Onsite radio and unauthenticated wireless assessor
Assessment requires approved site access, locations, SSIDs, test clients, onboarding material and controller or network evidence, selected specifically for guest isolation.
Evidence records the SSID, BSSID, radio, authentication, client-isolation or post-connect result relevant to guest isolation.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Guest isolation when the wireless feature is present at an approved location.

Limit: The conclusion is limited to the sampled guest isolation; radio results are location and time bound; disruptive RF actions require separate written authority.

Rogue and lookalike conditionsDamocles observes and, where expressly authorised, establishes controlled rogue or lookalike conditions to test user and control response.Onsite radio and unauthenticated wireless assessor
Assessment requires approved site access, locations, SSIDs, test clients, onboarding material and controller or network evidence, selected specifically for rogue and lookalike conditions.
Evidence records the SSID, BSSID, radio, authentication, client-isolation or post-connect result relevant to rogue and lookalike conditions.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Rogue and lookalike conditions when the wireless feature is present at an approved location.

Limit: The conclusion is limited to the sampled rogue and lookalike conditions; radio results are location and time bound; disruptive RF actions require separate written authority.

Downgrade conditionsDamocles checks whether authorised clients can be induced to use weaker advertised or negotiated security without disruptive RF activity.Onsite radio and unauthenticated wireless assessor
Assessment requires approved site access, locations, SSIDs, test clients, onboarding material and controller or network evidence, selected specifically for downgrade conditions.
Evidence records the SSID, BSSID, radio, authentication, client-isolation or post-connect result relevant to downgrade conditions.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Downgrade conditions when the wireless feature is present at an approved location.

Limit: The conclusion is limited to the sampled downgrade conditions; radio results are location and time bound; disruptive RF actions require separate written authority.

Network segmentationDamocles maps SSIDs to VLANs or policy segments and validates representative allowed and denied post-association paths.Onsite radio and unauthenticated wireless assessor
Named source and destination test points, expected flow matrix and a safe test window.
Source-to-destination results linked to rule, route or boundary evidence.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Performed when both ends of the network path and the enforcing device are owned or expressly authorised for testing.

Limit: Results cover the tested source, destination, protocol and route; testing stops on instability and does not authorise third-party or denial-of-service activity.

Post-connect accessDamocles tests the actual DNS, internet, internal and management access assigned to supplied corporate or guest clients.Supplied corporate or guest wireless client
Assessment requires approved site access, locations, SSIDs, test clients, onboarding material and controller or network evidence, selected specifically for post-connect access.
Evidence records the SSID, BSSID, radio, authentication, client-isolation or post-connect result relevant to post-connect access.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Post-connect access when the wireless feature is present at an approved location.

Limit: The conclusion is limited to the sampled post-connect access; radio results are location and time bound; disruptive RF actions require separate written authority.

Onsite and radio constraintsDamocles records site position, antenna, channel, interference and signal limitations for every radio observation.Onsite radio and unauthenticated wireless assessor
Assessment requires approved site access, locations, SSIDs, test clients, onboarding material and controller or network evidence, selected specifically for onsite and radio constraints.
Evidence records the SSID, BSSID, radio, authentication, client-isolation or post-connect result relevant to onsite and radio constraints.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Onsite and radio constraints when the wireless feature is present at an approved location.

Limit: The conclusion is limited to the sampled onsite and radio constraints; radio results are location and time bound; disruptive RF actions require separate written authority.

Deauthentication and production safetyDamocles documents deauthentication and disruptive RF exclusions and performs such activity only with written authority, a controlled window and stopping criteria.Supplied corporate or guest wireless client
Assessment requires approved site access, locations, SSIDs, test clients, onboarding material and controller or network evidence, selected specifically for deauthentication and production safety.
Evidence records the SSID, BSSID, radio, authentication, client-isolation or post-connect result relevant to deauthentication and production safety.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Deauthentication and production safety when the wireless feature is present at an approved location.

Limit: The conclusion is limited to the sampled deauthentication and production safety; radio results are location and time bound; disruptive RF actions require separate written authority.

Framework and control mappings1 governed evidence mappings
Where scoped technical evidence maps to approved security frameworks and control objectives.
Framework and controlsMapping typeWhat Damocles assessesEvidence producedApplicability and limits
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
Framework-level context
ContextualThe engagement produces point-in-time technical evidence about the configured and observed security behaviour within the authorised Wireless penetration testing scope.Coverage status, procedure results and findings can inform the customer’s control assessment and risk treatment records.

Applies: Framework-level context is provided when the customer uses NIST SP 800-53 to organise its security control program.

Limit: No individual NIST control is published as verified; organisational implementation, continuous operation, governance and complete catalogue coverage remain outside the engagement.

Assurance boundary: Damocles maps assessed coverage and findings to agreed security frameworks and control objectives. This provides traceable technical evidence that may support risk, assurance and audit activities. A penetration test does not by itself certify an organisation, establish complete compliance with a framework or confirm the effectiveness of controls outside the authorised scope.

Report and evidence outputs6 controlled output types

Authorised scope and rules of engagement

Records authorised scope and rules of engagement produced from the authorised Wireless penetration testing work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Coverage matrix

Records coverage matrix produced from the authorised Wireless penetration testing work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Retest and residual-risk record

Records retest and residual-risk record produced from the authorised Wireless penetration testing work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

SSID and authentication inventory

Records ssid and authentication inventory produced from the authorised Wireless penetration testing work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Radio and client-isolation results

Records radio and client-isolation results produced from the authorised Wireless penetration testing work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Post-connect reachability record

Records post-connect reachability record produced from the authorised Wireless penetration testing work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.
What you receive

A prioritised report with validated wireless access and trust findings, evidence, remediation guidance and retest results.

Attack paths we look for

Wireless attack paths that create unauthorised access or an internal foothold.

The exact techniques depend on the wireless design, security mode, location and written authority.

CR

Weak credential model

Shared, guessable, reusable or poorly controlled credentials that allow unintended access.

ON

Onboarding weakness

Unsafe provisioning, enrolment or certificate processes that allow untrusted clients to join.

CI

Client exposure

Missing isolation or unsafe peer access that exposes connected devices to each other.

SG

Segmentation failure

Wireless networks reaching internal services or zones beyond the intended policy.

RG

Rogue or lookalike risk

Conditions that make clients or users vulnerable to unauthorised or impersonated wireless infrastructure where testing is authorised.

PC

Post-connect compromise path

A wireless foothold chained with internal services, identities or management access.

Engagement options

Choose the wireless networks and post-connect depth that need assurance.

The scope identifies sites, SSIDs, security modes, test locations, supplied accounts and connected network ranges.

Corporate
CW

Corporate Wi-Fi assessment

Assess corporate wireless authentication, encryption and internal access controls.

Guest
GW

Guest Wi-Fi assessment

Assess isolation, internet-only expectations, captive controls and access to internal resources.

Operational
OT

Operational or device wireless

Assess approved operational, IoT or device-focused wireless where production safety permits.

Combined
CP

Wireless + internal assessment

Test what an attacker could do after gaining the approved wireless foothold.

What you receive

Evidence showing whether the wireless boundary holds before and after a client connects.

Findings distinguish radio/access control issues from network and segmentation consequences.

WS

Wireless scope summary

Assessed SSIDs, locations, security modes and authorised client conditions.

AU

Authentication findings

Evidence of weaknesses in credential, certificate or onboarding controls.

SG

Segmentation findings

Access observed between wireless and protected networks or clients.

PC

Post-connect findings

Services and attack paths available after connection.

RP

Remediation priorities

Changes to authentication, isolation, segmentation and operational configuration.

RR

Retest evidence

Verification of agreed wireless and segmentation fixes where included.

Remediation and retesting

Retesting verifies both the wireless control and the network access that depended on it.

Damocles can retest agreed wireless findings after configuration or segmentation changes and confirm whether the original access condition remains possible.

New sites, SSIDs, access-point designs or materially changed network paths are treated as new scope where they extend beyond the original assessment.

Testing delivery

A controlled technical engagement without turning the service page into a methodology manual.

The commercial scope comes first. Delivery is then controlled through written authority, agreed safety boundaries and a clear retest path.

01

Scope and authorise

Confirm targets, ownership, attacker perspective, accounts, exclusions, timing, contacts and prohibited activity.

02

Test and validate

Perform the authorised manual and technical testing required to prove or disprove the attack paths in scope.

03

Report and brief

Provide evidence, impact, affected scope, remediation priorities and a technical walkthrough with the people responsible for the fix.

04

Retest

Reproduce agreed findings after remediation and record whether they are resolved, reduced or still exploitable.

Scope boundaries

Wireless testing is performed only against approved networks, locations and techniques.

High-impact radio interference, uncontrolled deauthentication, testing of neighbouring networks and actions that could disrupt critical wireless devices are excluded unless expressly authorised and safely controlled.

Physical security and social engineering are separate services unless specifically added to the engagement.

Scope the right test

Tell us the sites, SSIDs, security modes and connected networks that need to be tested.

We will define the onsite requirements, wireless scope, post-connect testing, safety controls and retest allowance.