Flagging Malware is hard, and research/dev tools are always behaving at least similar to Malware (because we want to get data/do stuff regular users won't do).
making an exception for such a heuristic is, in all cases, wrong since it will always be abused.
The actual answer is: Defender needs a PUP category.
Nirsoft tools? Bam, "virus" and "malware". How dare you!
Tailscale website? Uh-oh, ZScaler thinks that's a "remote access tool" so you're being given a click-through formal warning!
The Framework website? Uh-oh, .work is a bad TLD! Can't browse to that, it could be evil!