Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →
All 5 checks on this page
- Wireless access points observed nearby
- Ensure No Possible Evil Twin Attack Is Detected
- Wireless networks observed nearby
- Ensure No Insecure Wireless Networks Are Detected Nearby
- Ensure Endpoints Are Not Connected To A Network With A Possible Evil Twin Access Point
- The wireless networks endpoints are connected to
- Ensure Endpoints Are Not Connected To Insecure Wireless Networks
- Ensure Endpoints Are Not Connected To A Possible Evil Twin Access Point
Wireless access points observed nearby
Ensure No Possible Evil Twin Attack Is Detected
Finding: Another radio is impersonating this wireless network (possible evil twin attack).
This rule inspects a single wireless access point. This rule fails when more than one transmitter has been seen beaconing this access point's SSID and BSSID.
A BSSID is a radio's hardware address, so exactly one transmitter should ever beacon a given network name and hardware address pair. The competing beacons are recorded on the access point as each endpoint's wireless scan is collected, so the check reads only this object. The transmitters are told apart by the channel they beacon on — one radio beacons on one channel — so an attacker sitting on the exact channel of the radio they are cloning is not separable this way and is not detected here.
The rule fails on the recorded detection, not on whether the impostor is transmitting at this moment. An access point is visible only to endpoints within radio range, so an impostor that has gone quiet, moved, or is simply out of range of whichever endpoint scanned most recently is not evidence the attack did not happen. The finding reports separately whether the impostor is still audible. The detection clears when it ages out of your organization's data retention window.
Rationale: An attacker who clones both the SSID and the BSSID of a legitimate access point is running an evil twin. They de-authenticate the legitimate access point's clients with forged management frames, then out-shout it with a stronger signal so those clients re-associate to the attacker's radio on the way back. The attacker then sits between the client and the network.
Impact: Traffic from every device drawn onto the attacker's radio passes through the attacker, who can read anything unencrypted, inject content, harvest credentials through a fake captive portal, and pivot into the network from there. Two radios sharing one identity also wrecks the air on its own: client frames collide, and devices roam back and forth between the two, losing connectivity.
Remediation
Treat the affected wireless network as hostile. Disconnect endpoints from it, then use the reported SSID, BSSID, and the channels of the competing beacons to physically locate and remove the unauthorized radio — the impersonating beacon is usually the stronger one. Verify each legitimate access point's BSSID and channel against your wireless infrastructure inventory. To prevent the attack: enable 802.11w Management Frame Protection so clients reject the forged de-authentication frames that drive them onto the twin, move from a pre-shared key to WPA3-Enterprise so a cloned access point cannot complete mutual authentication, and deploy a WIDS/WIPS that baselines your authorized radios. Report the incident to your security team.
- Risks
- High Profile Threat, Unprotected Data
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Wireless networks observed nearby
Ensure No Insecure Wireless Networks Are Detected Nearby
Finding: An insecure wireless network (weak authentication or cipher) is visible.
This rule inspects a wireless (Wi-Fi) network that has been seen by an endpoint's WLAN interface. This rule fails when the network advertises an insecure 802.11 authentication algorithm (such as open, WEP, dynamic WEP, or a legacy WPA mode) or an insecure cipher (such as WEP or TKIP), as reported by the platform's insecureAuthAlgo / insecureCipherAlgo classification.
Rationale: Open and WEP/TKIP-based networks provide little or no confidentiality and are trivial to intercept or join. Their presence near managed endpoints is a risk, and an unexpected insecure SSID can also indicate a rogue or evil-twin access point.
Impact: Endpoints that associate with an insecure network expose their traffic to interception and manipulation on the local RF segment.
Remediation
This is an awareness finding for an insecure wireless network broadcasting in range of your endpoints. If the network is yours, reconfigure its access points to require WPA2 or WPA3 with AES/GCMP and disable open, WEP, and TKIP. If it is not yours, treat it as a potential rogue or evil-twin access point and ensure endpoints are configured not to automatically join open or weak networks.
- Framework mappings
- CIS Controls v8: 12.6 Use of Secure Network Management and Communication Protocols
- NIST SP 800-53 Rev. 5: AC-18 Wireless Access; SC-23 Session Authenticity; SI-4 System Monitoring
- NIST SP 800-171 Rev. 2: 3.1.17 Protect wireless access using authentication and encryption; 3.13.1 Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems; 3.13.15 Protect the authenticity of communications sessions
- CMMC 2.0 Level 1: SC.L1-b.1.x Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems
- CMMC 2.0 Level 2: AC.L2-3.1.17 Protect wireless access using authentication and encryption; SC.L2-3.13.1 Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems; SC.L2-3.13.15 Protect the authenticity of communications sessions
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure Endpoints Are Not Connected To A Network With A Possible Evil Twin Access Point
Finding: The wireless network this endpoint is connected to has had an access point flagged as a possible evil twin in the last 30 days.
This rule finds endpoints connected to a wireless network on which an access point flagged as a possible evil twin has been seen in the last 30 days: a hardware address advertised under more than one network name. This rule fails for each such endpoint.
Rationale: An evil twin on the network an endpoint uses can lure it, or other devices, onto attacker equipment at the next reconnect or roam, even if its current access point is legitimate.
Impact: Once joined, the attacker can intercept, modify, or redirect traffic and harvest credentials.
Remediation
Investigate and physically locate the access point flagged as a possible evil twin on this wireless network. Confirm the legitimate access points' hardware addresses with your network team, and prefer WPA2/WPA3-Enterprise so clients authenticate the network before joining it.
- Risks
- High Profile Threat, Unprotected Data
- MITRE ATT&CK tactic
- Credential Access (TA0006)
The wireless networks endpoints are connected to
Ensure Endpoints Are Not Connected To Insecure Wireless Networks
Finding: An endpoint is connected to a wireless network using insecure authentication or a weak cipher.
This rule inspects an endpoint WLAN interface's active connection to a wireless network. This rule fails when the connection's authentication algorithm is insecure (open, WEP, dynamic WEP, or a legacy WPA mode) or its cipher is insecure (WEP or TKIP).
Rationale: When an endpoint is actively connected over open or WEP/TKIP-based Wi-Fi, its network traffic has little or no cryptographic protection on the wireless link and can be intercepted or altered by anyone in RF range.
Impact: Credentials, session tokens, and sensitive data traversing the connection are exposed to eavesdropping and adversary-in-the-middle attacks.
Remediation
Disconnect the endpoint from the insecure wireless network. Configure the endpoint (or its Wi-Fi profile / MDM policy) to require WPA2 or WPA3 with AES/GCMP and to refuse open, WEP, and TKIP networks. If the network is corporate, upgrade its access points to a secure authentication method and cipher; otherwise move the endpoint to a trusted network.
- Framework mappings
- CIS Controls v8: 12.6 Use of Secure Network Management and Communication Protocols
- NIST SP 800-53 Rev. 5: AC-18 Wireless Access; SC-23 Session Authenticity; SI-4 System Monitoring
- NIST SP 800-171 Rev. 2: 3.1.17 Protect wireless access using authentication and encryption; 3.13.1 Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems; 3.13.15 Protect the authenticity of communications sessions
- CMMC 2.0 Level 1: SC.L1-b.1.x Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems
- CMMC 2.0 Level 2: AC.L2-3.1.17 Protect wireless access using authentication and encryption; SC.L2-3.13.1 Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems; SC.L2-3.13.15 Protect the authenticity of communications sessions
- Risks
- High Profile Threat, Unprotected Data
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure Endpoints Are Not Connected To A Possible Evil Twin Access Point
Finding: This endpoint is connected to a wireless access point flagged as a possible evil twin.
This rule finds endpoints whose wireless interface is connected to an access point flagged as a possible evil twin: a hardware address advertised under more than one network name. This rule fails for each such endpoint.
Rationale: An evil twin impersonates a trusted wireless network so nearby devices join it instead. An endpoint connected to one sends its traffic through equipment the attacker controls.
Impact: The attacker can intercept, modify, or redirect the endpoint's traffic, harvest credentials from captive portals or cleartext protocols, and serve malicious content.
Remediation
Disconnect the endpoint from the wireless network and forget the network profile. Confirm the legitimate access point's hardware address with your network team, then investigate and physically locate the impersonating access point. Have users verify network identity before connecting, and prefer WPA2/WPA3-Enterprise so clients authenticate the network.
- Risks
- High Profile Threat, Unprotected Data
- MITRE ATT&CK tactic
- Credential Access (TA0006)