In a major malware outbreak, you must load an Extra.DAT file to protect client systems until the next scheduled content update. You might need to load an Extra.DAT file on client systems to suppress detections that are considered false positives until the next scheduled content update.
Best practice: For information on how to create a report of which computers have an Extra.DAT file installed, see KB59410.
Download the Extra.DAT file:
Click the download link supplied by Trellix Advanced Research Center, specify a location to save the Extra.DAT file, and then click Save.
If needed, unzip the EXTRA.ZIP file.
Select Menu → Software → Main Repository.
Select Actions → Check in Packages.
Select Extra DAT (.DAT), browse to the download folder, and then click Open.
Confirm your selection, then click Next.
The Main Repository page displays the new content package in the Name column.
Replicate the Extra.DAT file to mirror sites, if applicable. Run a Trellix Agent Mirror Repositories client task.
Best practice: When you finish using the Extra.DAT file, remove it from the Main Repository and run a Mirror Repositories client task to remove it from distributed repositories. Removing the Extra.DAT file prevents clients from downloading it during an update. By default, detection for the new threat in the Extra.DAT file is ignored once the new detection definition is added to the daily content files.
Deploy the Extra.DAT file to client systems using a Trellix Agent Product Update client task.
Send an agent wake-up call to update the client systems with the Extra.DAT file.