Hi @jmcg ,
Thankyou for reaching us on community.
Unfortunately, ENS Access protection does not have this feature to add a custom popup.
Another way you can avoid these kind of files is my adding the filename in ENS treat prevention policy under potentially unwanted program. so that tor.exe will be deleted the next time it is accessed.
Steps :
1. Log in to EPO -> policy catalog.
2. Endpoint security Threat prevention -> Options ->
3. Select the policy that you would like to edit.
4. Scroll down to "Potentially Unwanted Program Detections".
5. click "add".
6. Enter the file name. example : tor.exe -> click save
7. save the policy -> enforce the changes to the client machine with a wakeup agent call or "collect and send props".
I hope you find this helpful!
-Rohit Francis