SV SurfaceVector Cyber Operations Center

Free defensive cyber tools

Trellix ePO Threat Event Parser

Organize verbose Trellix event details into an analyst-ready summary while keeping event data inside the browser.

  • Identify endpoint, source, target, process, action, severity, and detection fields.
  • Classify removable-media, malware, ransomware, containment, and access-protection events.
  • Generate investigation recommendations and exportable case notes.

Launch this tool

SurfaceVector cybersecurity tools

Authoritative cybersecurity sources

SurfaceVector connects defensive workflows with resources from CISA, the CVE Program, FIRST, NIST, and DISA STIGs.