Endpoint Protection

 View Only

 Anyone else seeing SONAR detections for rdpclip.exe as ACM.Rdp-Lnch!g1?

Guido Janssen's profile image
Guido Janssen posted Aug 12, 2025 04:52 AM

Hi all,

We've recently noticed a spike in SONAR detections for rdpclip.exe flagged as ACM.Rdp-Lnch!g1 in our SEP logs. From what I understand, this is part of the Adaptive Protection policy and might be related to behavioral heuristics rather than actual malware.

Are other organizations seeing similar detections? Just trying to determine if this is a widespread false positive or something we should investigate further.

Thanks in advance!

Paul Mal's profile image
Paul Mal

I'm seeing the same thing.

Russ_V's profile image
Broadcom Employee Russ_V

Guido Janssen,

Thanks for using the Broadcom Community!


Yes, you are correct!  Detections with "ACM" at the start of the detection name are associated with our Adaptive Protection technology. 

For ALL options involving Adaptive Protection "tuning" see this link: 
https://techdocs.broadcom.com/us/en/symantec-security-software/endpoint-security-and-management/endpoint-security/sescloud/Using-Adaptive-Protection/Behavioral-Isolation-Heat-Map.html

In the case, the application is trusted and you need to add an Adaptive Protection exclusion refer to this link for the steps: 
https://techdocs.broadcom.com/us/en/symantec-security-software/endpoint-security-and-management/endpoint-security/sescloud/Using-Adaptive-Protection/creating-custom-exceptions-for-adaptive-protection.html

If you require further assistance beyond the above, kindly open a case with Broadcom Support and we'll take a look into this behavior and provide our suggestions.

Thanks,

Russ_V

Russ_V's profile image
Broadcom Employee Russ_V

Guido Janssen, 

Thanks for using the Broadcom Community! 

In response to your query, yes the "ACM" specific detections are referring to Adaptive Protection detections. 

For more information regarding the options available to "tune" your Adaptive Protection policy see here

In the case you want to create Adaptive Protection exclusions see here.

If you need guidance on how to do either of the above, kindly open a case with Support for assistance. 

Best,

Russ_V