Configure Roll Back AMCore Content client tasks from the Client Task Catalog, then assign them to systems in the System Tree.
Trellix ENS stores the currently loaded content file and the previous two versions in the Program Files\Common Files\McAfee\Engine\content folder. If needed, you can revert to a previous version.
Note
Exploit Prevention content updates cannot be rolled back.
Select Menu → Client Tasks → Client Task Catalog.
From Client Task Types, select Endpoint Security Threat Prevention → Remove AMCore Content.
Ensure that Roll Back AMCore Content is selected, then click OK.
Configure the settings and click Save.
Under Actions, click the Assign link, specify the computers to assign the task to, then click OK.
Click 2 Schedule to schedule the task, then click Save.
See the ePO - On-prem Help for schedule information and the Client Task Assignment Builder.