The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

How content files work

Prev Next

When searching files for threats, the scan engine compares the contents of the scanned files to known threat information stored in the AMCore content files. Exploit Prevention uses its own content files to protect against exploits.

Note

Exploit Prevention is not supported in the ARM architecture.

Trellix Advanced Research Center finds and adds known threat information (signatures) to the content files. With the signatures, content files include information about cleaning and counteracting damage that the detected malware can cause. New threats appear, and Trellix Advanced Research Center releases updated content files, regularly.

Caution

If the signature of a threat isn't in the installed content files, the scan engine can't detect that threat, leaving your system vulnerable to attack.

Trellix ENS stores the currently loaded content file and the previous two versions in the Program Files\Common Files\McAfee\Engine\content folder. If needed, you can revert to a previous version.

If new malware is discovered and extra detection is required outside of the regular content update schedule, Trellix Advanced Research Center releases an Extra.DAT file. ePO - On-prem

AMCore content package

Trellix Advanced Research Center releases AMCore content packages daily by 7:00 p.m. (GMT/UTC). If a new threat warrants it, daily AMCore content files might be released earlier and, sometimes, releases might be delayed.

To receive alerts regarding delays or important notifications, subscribe to the Support Notification Service (SNS). See KB67828.

The AMCore content package contains updates to the Threat Prevention scan engine and signatures based on results of ongoing threat research.

Tip

Best practice: For answers to frequently asked questions about AMCore content files (V3 DAT), see KB82396.

Exploit Prevention content package

Note

Exploit Prevention is not supported in the ARM architecture.

The Exploit Prevention content package includes:

  • Memory protection signatures — Generic Buffer Overflow Protection (GBOP), caller validation, Generic Privilege Escalation Prevention (GPEP), and Targeted API Monitoring.

  • Network Intrusion Prevention signatures protect:

    • Systems located downstream in a network segment.

    • Servers and the systems that connect to them.

    • Against network denial-of-service attacks and bandwidth-oriented attacks that deny or degrade network traffic.

    Note

    Network Intrusion Prevention (Network IPS) is not supported in the ARM architecture.

  • Access Protection signatures — Files, Registry key, Registry value, Processes, and Services.

  • Application Protection List — Processes that Exploit Prevention protects.

Exploit Prevention content is similar to the McAfee Host IPS content files. See KB51504. To view KB51504, you must first log on to the ServicePortal and then search the Knowledge Center for KB51504.

Trellix releases new Exploit Prevention content files once a month. To make sure that Threat Prevention uses the latest content files, retrieve these files from Trellix and update your systems regularly.