← All walkthroughs

Wi-Fi (WPA2) to the internal network

Capturing a WPA2 handshake, cracking the pre-shared key offline, and joining the wireless network turns radio range into an internal foothold.

Corporate WPA2-PSK wireless Intermediate WirelessCredential AccessNetwork
Authorized testing only. This is a conceptual, defensive-aware walkthrough that maps an attack path to MITRE ATT&CK, detection and mitigation, and links to references for the detail. It is not a copy-paste playbook. Use it only against systems you own or are explicitly permitted to test.

Scenario

An authorized wireless assessment within radio range of the target. Testing of the in-scope WPA2-PSK network is approved. The objective is to show whether the wireless pre-shared key can be recovered and used to reach the internal network.

Practice this path: MITRE ATT&CK
  1. 1

    Reconnaissance / Collection

    Capture a WPA2 four-way handshake

    Monitor the in-scope wireless network, enumerate its BSSID and clients, and capture a four-way handshake (optionally by waiting for a natural reconnection) without disrupting users.

    Detection

    A sudden drop and reconnection of a client, or an interface in monitor mode nearby, can be noticed by a wireless IDS/WIPS.

    Mitigation

    Deploy a wireless IPS, prefer WPA3/SAE which resists offline cracking, and watch for deauthentication floods.

  2. 2

    Credential Access

    Recover the pre-shared key offline

    Run an offline dictionary/mask attack against the captured handshake. A weak or guessable passphrase is recovered; a long random one is reported as resistant — the strength of the PSK is the finding.

    Detection

    Offline cracking is invisible to the target by design — which is exactly why passphrase strength and rotation are the control.

    Mitigation

    Use a long, random passphrase (or 802.1X/EAP with per-user credentials), and rotate it after staff changes.

  3. 3

    Initial Access

    Join the wireless network

    Authenticate to the WLAN with the recovered key to obtain an internal IP, or, where in scope, assess whether a rogue access point (evil twin) would lure clients — demonstrating the exposure without harming users.

    Detection

    A new, unrecognised device associating to the WLAN, or a duplicate SSID broadcasting, is detectable with WLAN client inventories and WIPS.

    Mitigation

    Segment wireless from sensitive internal zones, require 802.1X with certificate validation, and enable rogue-AP detection.

    References aircrack-ng
  4. 4

    Discovery

    Map the internal network

    From the wireless segment, enumerate reachable hosts and services to show what the wireless foothold exposes, staying within the approved internal scope.

    Detection

    Host and service sweeps from a wireless client are visible to internal network monitoring and NAC.

    Mitigation

    Place wireless clients behind a firewall with least-privilege rules, and use NAC to limit what a new device can reach.

Key takeaways

  • A WPA2 network is only as strong as its passphrase — a weak PSK is an internal foothold at radio range.
  • WPA3/SAE and 802.1X remove the offline-crackable shared secret entirely.
  • Segment and monitor the wireless network so that joining it is not the same as being inside.