The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Download and deploy an Extra.DAT file to client systems from ePO - On-prem

Prev Next

In a major malware outbreak, you must load an Extra.DAT file to protect client systems until the next scheduled content update. You might need to load an Extra.DAT file on client systems to suppress detections that are considered false positives until the next scheduled content update.

Best practice: For information on how to create a report of which computers have an Extra.DAT file installed, see KB59410.

Task
  1. Download the Extra DAT (.DAT) file:

    1. Click the download link supplied by Trellix Advanced Research Center, specify a location to save the Extra.DAT file and then click Save..

    2. If needed, unzip the EXTRA.ZIP file.

  2. Select MenuSoftwareMain Repository.

  3. Select ActionsCheck in Packages.

  4. Select Extra DAT (.DAT), browse to the location where you downloaded the file, then click Open.

  5. Confirm your selection, then click Next.

    The Main Repository page displays the new content package in the Name column.

  6. Replicate the Extra.DAT file to mirror sites, if applicable. Run a Trellix Agent Mirror Repositories client task.

    Best practice: When you finish using the Extra.DAT file, remove it from the Main Repository and run a Mirror Repositories client task to remove it from distributed repositories. Removing the Extra.DAT file prevents clients from downloading it during an update. By default, detection for the new threat in the Extra.DAT file is ignored once the new detection definition is added to the daily content files.

  7. Deploy the Extra.DAT file to client systems using a Trellix Agent Product Update client task.

  8. Send an agent wake-up call to update the client systems with the Extra.DAT file.