Well in the past, a signed Dutch program with few users was always blocked by that ASR rule and allowed by WDAC (before we bought new laptops, we were bith using WHHL). The stupid thing about that program was that one could not decline updates. So I ended up disabling that ASR rule on het former laptop.
The logic behind that ASR rule is illlustrated with a saying "to survice a lion attack you don't have to run fater than the lion, just run faster than another in the herd" So when 1000 people are using that program without being infected it has a high likelyhood of being benign.