The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Update command line interface

Prev Next

The update command line interface enables to you update the scan engine, AMCore content, and Exploit Prevention from the command line or as part of a batch file. All users can run updates, regardless of the interface mode for the Trellix Endpoint Security (ENS) Client.

Note

Exploit Prevention is not supported in the ARM architecture.

Prerequisites

The Threat Prevention service (mfetp.exe) must already be running for amcfg.exe to run.

Syntax: Update command line interface

The update syntax for amcfg.exe is:

installation_path\amcfg.exe /update

installation_path — C:\Program Files\McAfee\Endpoint Security\Threat Prevention by default

Examples: Update command line interface

Open a command prompt and change to the installation location of amcfg.exe to run these example commands. By default, amcfg.exe is located in the C:\Program Files\McAfee\Endpoint Security\Threat Prevention folder.

To...

Run this command

Run an update.

amcfg.exe /update