The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Handling new malware with Extra.DAT files

Prev Next

When new malware is discovered and extra detection is required, Trellix Advanced Research Center releases an Extra.DAT file containing information that Threat Prevention uses to handle the new malware.

Threat Prevention supports using only one Extra.DAT file at a time. In a situation where you need both a positive Extra.DAT file for Threat Prevention and a negative Extra.DAT for Adaptive Threat Protection, you can request a combined file from Trellix Advanced Research Center.

Each Extra.DAT file has an expiration date built in. When the Extra.DAT file is loaded, this expiration date is compared against the build date of the AMCore content installed on the system. If the build date of the AMCore content is newer than the Extra.DAT expiration date, the Extra.DAT is considered expired. It is no longer loaded and used by the engine. During the next update, the Extra.DAT is removed from the system.

If the next update of AMCore content includes information in the Extra.DAT, the Extra.DAT is removed.

Trellix ENS stores Extra.DAT files in: c:\Program Files\Common Files\McAfee\Engine\content\avengine\extradat folder.