To change the version of AMCore content on the client system, use Trellix Endpoint Security (ENS) Client.
Endpoint Security stores the currently loaded content file and the previous two versions in the Program Files\Common Files\McAfee\Engine\content folder. If needed, you can revert to a previous version.
Exploit Prevention content updates cannot be rolled back.
Open the Trellix Endpoint Security (ENS) Client.
From the Action menu
, select Roll Back AMCore Content.From the drop-down, select the version to load.
Click Apply.
The detections in the loaded AMCore content file take effect immediately.
Note
Exploit Prevention is not supported in the ARM architecture.