The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

How content files work

Prev Next

AMCore content files include updates to scanners, engines, and rules that Adaptive Threat Protection uses to dynamically compute the reputation and acceptable behavior of files and processes on client systems.

Trellix Advanced Research Center adds rules to the content files. With the rules, content files include information about preventing malware behaviors. New threats appear, and Trellix Advanced Research Center releases updated content files, regularly.

Trellix ENS stores the currently loaded content file and the previous two versions in the Program Files\Common Files\McAfee\Engine\content folder. If needed, you can revert to a previous version.

If Adaptive Threat Protection determines that a detection is a false positive, Trellix Advanced Research Center might release a negative Extra.DAT file to suppress the detection until the next content update. Deploying a negative Extra.DAT is optional. If the TIE server is present, you can change the reputation score to eliminate the false positive. For information, see KB82922.

AMCore content package

Trellix Advanced Research Center releases AMCore content packages daily by 7 p.m. / 19:00 (GMT/UTC). If a new threat warrants it, daily AMCore content files might be released earlier and, sometimes, releases might be delayed.

To receive alerts regarding delays or important notifications, subscribe to the Support Notification Service (SNS). See KB67828.

The AMCore content package includes these Adaptive Threat Protection components:

  • Adaptive Threat Protection — Scanner and rules

    Contains updates to the scanner and Adaptive Threat Protection rules to dynamically compute the reputation of files and processes on the client systems.

    These rules appear in ePO - On-prem in the Server SettingsAdaptive Threat Protection page. You can change the state, for example Enabled or Disabled of non-Mandatory rules only. For information about ATP rules, including rule IDs and their corresponding rule names and descriptions, see KB82925.

    For information about the latest ATP content, see the Trellix ATP Security Content Release Notes.

  • ML Protect — Engine and content

    Contains updates to the ML Protect scan engine and rules based on results of ongoing threat research. ML Protect is a component of the ATP module.

    To make sure that Trellix ENS uses the latest content files and engine, retrieve these files from Trellix and update your systems daily.

The version numbers for Adaptive Threat Protection content and ML Protect content appear in Trellix Endpoint Security (ENS) Client in the About page.

Best practice For answers to frequently asked questions about AMCore content files (V3 DAT), see KB82396.

Rules for ATP and the Threat Intelligence Exchange module for Trellix ENS or Threat Prevention

If you manage clients running Adaptive Threat Protection and the Threat Intelligence Exchange module for Trellix ENS or Threat Prevention from the same ePO - On-prem server, the rules displayed in the Server Settings page depend on the content checked in to the Main Repository. If the AMCore Content Package is checked in, ATP displays rules from that package. Otherwise, ATP displays rules from the Threat Intelligence Exchange module Content . If neither are present in the Main Repository, the Server Settings page for Adaptive Threat Protection is blank.

ATP displays rules from only one content source.

Note

If an update to Threat Intelligence Exchange module Content includes changes to rules, those changes don't appear in Server Settings (and can't be edited) until AMCore Content Package is updated with those changes.