The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Handling new false positives with Extra.DAT files

Prev Next

If Adaptive Threat Protection determines that a detection is a false positive, Trellix Advanced Research Center might release a negative Extra.DAT file to suppress the detection until the next content update.

Deploying a negative Extra.DAT is optional. If the TIE server is present, you can change the reputation score to eliminate the false positive. For information, see KB82922.

ATP supports using only one Extra.DAT file at a time. In a situation where you need both a negative Extra.DAT file and a positive Extra.DAT file for Threat Prevention, you can request a combined file from Trellix Advanced Research Center.

Each Extra.DAT file has an expiration date built in. When the Extra.DAT file is loaded, this expiration date is compared against the build date of the AMCore content installed on the system. If the build date of the AMCore content is newer than the Extra.DAT expiration date, the Extra.DAT is considered expired. It is no longer loaded and used by the engine. During the next update, the Extra.DAT is removed from the system.

If the next update of AMCore content includes information in the Extra.DAT, the Extra.DAT is removed.

Trellix ENS stores Extra.DAT files in the c:\Program Files\Common Files\McAfee\Engine\content\avengine\extradat folder.