Hoxy
ServicesOfferingsProjectsToolsAbout
faConsultation
Hoxy

Hoxy Platform — precise cybersecurity for growing organizations.

Unit 1204, 12th Floor, Aseman Tower, Valiasr St., above Saei Park, Tehran, Iran

Product

ServicesOfferingsToolsDownloads

Company

AboutProjectsFAQContact

Legal

PrivacyTermsConfidentialitySLA

Phone: 021-9109-4580

Email: info@hoxy.ir

© 2026 Hoxy. All rights reserved by Hoxy.

hoxy.ir

Download center

Whitepapers, checklists, guides, and policy templates

Whitepaper

Ransomware Defense Whitepaper

Prevention, detection, and recovery framework for mid-to-large organizations.

  • •Common initial-access paths
  • •Isolated backups and restore testing
  • •Containment and crisis comms in the first 24 hours
  • •Board-level readiness metrics
Get via email

Checklist

Penetration Test Readiness Checklist

What to prepare before web and network penetration testing.

  • •Scope and RoE definition
  • •Access and test accounts
  • •Time window and point of contact
  • •Staging environment preparation
  • •Success criteria and retesting

Security Guide

Secure Coding Guide

Practical principles for web and API engineering teams.

  • •Input and output validation
  • •Object- and role-level access control
  • •Session and token management
  • •Safe secrets handling in CI/CD

Policy Template

Incident Response Policy Template

Customizable template for IR policy and roles.

  • •Incident severity definitions
  • •Roles and escalation chain
  • •Evidence handling and external communications
  • •Post-incident lessons learned
Get via email

Checklist

Zero Trust Maturity Checklist

Practical criteria for identity, device, network, and data on a Zero Trust path.

  • •MFA coverage and method quality
  • •Device inventory and health posture
  • •Segmentation and application-aware access
  • •Access logging and rapid revocation
  • •90-day progress metrics

Security Guide

Multi-cloud Security Baseline

Minimum recommended controls for AWS, Azure, and GCP in growing organizations.

  • •Org guardrails and deny-public policies
  • •Least-privilege IAM and temporary keys
  • •Deletion-protected audit logging
  • •Storage encryption and secrets
Get via email

Security Guide

SPF, DKIM, and DMARC Guide

Practical email authentication to reduce domain spoofing and phishing.

  • •SPF design without over-permission
  • •DKIM signing and key management
  • •Moving DMARC to reject
  • •Reading aggregate reports
  • •Coordination with email providers

Playbook Pack

SOC Starter Use-Case Pack

20 high-signal scenarios for initial SIEM/SOC launch or tuning.

  • •Identity and MFA abuse
  • •Endpoint persistence indicators
  • •Unusual data egress
  • •High-risk firewall and IAM changes
Get via email