---
title: Wireless Networks Security Controls: 5 Checks | Wartiva
description: The 5 checks Wartiva runs for wireless networks, beyond the CIS Benchmarks: what each one finds, why it matters, and how to fix it.
url: https://wartiva.com/policy-rules/wartiva/wireless-networks.html
updated: 2026-10-07
---

Wartiva Security Controls

# Wireless Networks: 5 Checks

Wartiva's Wireless Networks controls: evil twin access points and insecure wireless networks, both nearby and on the networks your endpoints actually connect to.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. [How Wartiva works →](https://wartiva.com/platform.html)

## Wireless access points observed nearby

### [Ensure No Possible Evil Twin Attack Is Detected](https://wartiva.com/policy-rules/wartiva/wireless-networks.html#no-possible-evil-twin-attack-is-detected)

High severity · Wartiva Security Controls · Wireless Networks

**Finding:** Another radio is impersonating this wireless network (possible evil twin attack).

This rule inspects a single wireless access point. This rule fails when more than one transmitter has been seen beaconing this access point's SSID and BSSID.

A BSSID is a radio's hardware address, so exactly one transmitter should ever beacon a given network name and hardware address pair. The competing beacons are recorded on the access point as each endpoint's wireless scan is collected, so the check reads only this object. The transmitters are told apart by the channel they beacon on — one radio beacons on one channel — so an attacker sitting on the exact channel of the radio they are cloning is not separable this way and is not detected here.

The rule fails on the recorded detection, not on whether the impostor is transmitting at this moment. An access point is visible only to endpoints within radio range, so an impostor that has gone quiet, moved, or is simply out of range of whichever endpoint scanned most recently is not evidence the attack did not happen. The finding reports separately whether the impostor is still audible. The detection clears when it ages out of your organization's data retention window.

**Rationale:** An attacker who clones both the SSID and the BSSID of a legitimate access point is running an evil twin. They de-authenticate the legitimate access point's clients with forged management frames, then out-shout it with a stronger signal so those clients re-associate to the attacker's radio on the way back. The attacker then sits between the client and the network.

**Impact:** Traffic from every device drawn onto the attacker's radio passes through the attacker, who can read anything unencrypted, inject content, harvest credentials through a fake captive portal, and pivot into the network from there. Two radios sharing one identity also wrecks the air on its own: client frames collide, and devices roam back and forth between the two, losing connectivity.

#### Remediation

Treat the affected wireless network as hostile. Disconnect endpoints from it, then use the reported SSID, BSSID, and the channels of the competing beacons to physically locate and remove the unauthorized radio — the impersonating beacon is usually the stronger one. Verify each legitimate access point's BSSID and channel against your wireless infrastructure inventory. To prevent the attack: enable 802.11w Management Frame Protection so clients reject the forged de-authentication frames that drive them onto the twin, move from a pre-shared key to WPA3-Enterprise so a cloned access point cannot complete mutual authentication, and deploy a WIDS/WIPS that baselines your authorized radios. Report the incident to your security team.

Risks

High Profile Threat, Unprotected Data

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

## Wireless networks observed nearby

### [Ensure No Insecure Wireless Networks Are Detected Nearby](https://wartiva.com/policy-rules/wartiva/wireless-networks.html#no-insecure-wireless-networks-are-detected-nearby)

Medium severity · Wartiva Security Controls · Wireless Networks

**Finding:** An insecure wireless network (weak authentication or cipher) is visible.

This rule inspects a wireless (Wi-Fi) network that has been seen by an endpoint's WLAN interface. This rule fails when the network advertises an insecure 802.11 authentication algorithm (such as open, WEP, dynamic WEP, or a legacy WPA mode) or an insecure cipher (such as WEP or TKIP), as reported by the platform's `insecureAuthAlgo` / `insecureCipherAlgo` classification.

**Rationale:** Open and WEP/TKIP-based networks provide little or no confidentiality and are trivial to intercept or join. Their presence near managed endpoints is a risk, and an unexpected insecure SSID can also indicate a rogue or evil-twin access point.

**Impact:** Endpoints that associate with an insecure network expose their traffic to interception and manipulation on the local RF segment.

#### Remediation

This is an awareness finding for an insecure wireless network broadcasting in range of your endpoints. If the network is yours, reconfigure its access points to require WPA2 or WPA3 with AES/GCMP and disable open, WEP, and TKIP. If it is not yours, treat it as a potential rogue or evil-twin access point and ensure endpoints are configured not to automatically join open or weak networks.

Framework mappings

- **CIS Controls v8**: 12.6 Use of Secure Network Management and Communication Protocols
- **NIST SP 800-53 Rev. 5**: AC-18 Wireless Access; SC-23 Session Authenticity; SI-4 System Monitoring
- **NIST SP 800-171 Rev. 2**: 3.1.17 Protect wireless access using authentication and encryption; 3.13.1 Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems; 3.13.15 Protect the authenticity of communications sessions
- **CMMC 2.0 Level 1**: SC.L1-b.1.x Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems
- **CMMC 2.0 Level 2**: AC.L2-3.1.17 Protect wireless access using authentication and encryption; SC.L2-3.13.1 Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems; SC.L2-3.13.15 Protect the authenticity of communications sessions

Risk

Unprotected Data

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure Endpoints Are Not Connected To A Network With A Possible Evil Twin Access Point](https://wartiva.com/policy-rules/wartiva/wireless-networks.html#endpoints-are-not-connected-to-a-network-with-a-possible-evil-twin-access-point)

High severity · Wartiva Security Controls · Wireless Networks

**Finding:** The wireless network this endpoint is connected to has had an access point flagged as a possible evil twin in the last 30 days.

This rule finds endpoints connected to a wireless network on which an access point flagged as a possible evil twin has been seen in the last 30 days: a hardware address advertised under more than one network name. This rule fails for each such endpoint.

**Rationale:** An evil twin on the network an endpoint uses can lure it, or other devices, onto attacker equipment at the next reconnect or roam, even if its current access point is legitimate.

**Impact:** Once joined, the attacker can intercept, modify, or redirect traffic and harvest credentials.

#### Remediation

Investigate and physically locate the access point flagged as a possible evil twin on this wireless network. Confirm the legitimate access points' hardware addresses with your network team, and prefer WPA2/WPA3-Enterprise so clients authenticate the network before joining it.

Risks

High Profile Threat, Unprotected Data

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

## The wireless networks endpoints are connected to

### [Ensure Endpoints Are Not Connected To Insecure Wireless Networks](https://wartiva.com/policy-rules/wartiva/wireless-networks.html#endpoints-are-not-connected-to-insecure-wireless-networks)

High severity · Wartiva Security Controls · Wireless Networks

**Finding:** An endpoint is connected to a wireless network using insecure authentication or a weak cipher.

This rule inspects an endpoint WLAN interface's active connection to a wireless network. This rule fails when the connection's authentication algorithm is insecure (open, WEP, dynamic WEP, or a legacy WPA mode) or its cipher is insecure (WEP or TKIP).

**Rationale:** When an endpoint is actively connected over open or WEP/TKIP-based Wi-Fi, its network traffic has little or no cryptographic protection on the wireless link and can be intercepted or altered by anyone in RF range.

**Impact:** Credentials, session tokens, and sensitive data traversing the connection are exposed to eavesdropping and adversary-in-the-middle attacks.

#### Remediation

Disconnect the endpoint from the insecure wireless network. Configure the endpoint (or its Wi-Fi profile / MDM policy) to require WPA2 or WPA3 with AES/GCMP and to refuse open, WEP, and TKIP networks. If the network is corporate, upgrade its access points to a secure authentication method and cipher; otherwise move the endpoint to a trusted network.

Framework mappings

- **CIS Controls v8**: 12.6 Use of Secure Network Management and Communication Protocols
- **NIST SP 800-53 Rev. 5**: AC-18 Wireless Access; SC-23 Session Authenticity; SI-4 System Monitoring
- **NIST SP 800-171 Rev. 2**: 3.1.17 Protect wireless access using authentication and encryption; 3.13.1 Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems; 3.13.15 Protect the authenticity of communications sessions
- **CMMC 2.0 Level 1**: SC.L1-b.1.x Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems
- **CMMC 2.0 Level 2**: AC.L2-3.1.17 Protect wireless access using authentication and encryption; SC.L2-3.13.1 Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems; SC.L2-3.13.15 Protect the authenticity of communications sessions

Risks

High Profile Threat, Unprotected Data

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure Endpoints Are Not Connected To A Possible Evil Twin Access Point](https://wartiva.com/policy-rules/wartiva/wireless-networks.html#endpoints-are-not-connected-to-a-possible-evil-twin-access-point)

High severity · Wartiva Security Controls · Wireless Networks

**Finding:** This endpoint is connected to a wireless access point flagged as a possible evil twin.

This rule finds endpoints whose wireless interface is connected to an access point flagged as a possible evil twin: a hardware address advertised under more than one network name. This rule fails for each such endpoint.

**Rationale:** An evil twin impersonates a trusted wireless network so nearby devices join it instead. An endpoint connected to one sends its traffic through equipment the attacker controls.

**Impact:** The attacker can intercept, modify, or redirect the endpoint's traffic, harvest credentials from captive portals or cleartext protocols, and serve malicious content.

#### Remediation

Disconnect the endpoint from the wireless network and forget the network profile. Confirm the legitimate access point's hardware address with your network team, then investigate and physically locate the impersonating access point. Have users verify network identity before connecting, and prefer WPA2/WPA3-Enterprise so clients authenticate the network.

Risks

High Profile Threat, Unprotected Data

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
