The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Change the AMCore content version on a client system

Prev Next

To change the version of AMCore content on the client system, use Trellix Endpoint Security (ENS) Client.

Trellix ENS stores the currently loaded content file and the previous two versions in the Program Files\Common Files\McAfee\Engine\content folder. If needed, you can revert to a previous version.

Task

Exploit Prevention content updates cannot be rolled back.

  1. Open the Trellix Endpoint Security (ENS) Client.

  2. From the Action menu GUID-A3B12F55-7EE9-4519-8FCA-9ACA85C3661F-low.png, select Roll Back AMCore Content.

  3. From the drop-down, select the version to load.

  4. Click Apply.

The detections in the loaded AMCore content file take effect immediately.

Note

Exploit Prevention is not supported in the ARM architecture.