Royal TS Generates

I use Royal TS to access remote VM's.  Last week, Sophos EDR has started generating an Investigation after each use.  Has anyone else seen this of have any thoughts? Classification rule is WIN-MITRE-Behavioral-TA0005-T1055.012

Has a risk value of 8

Detection Name HeapHeapProtect

Yet is shows Good Known Reputation

Seems a little counter intuitive