I think on Windows it's not only based on a missing signature. I sometimes get the "this file may damage your computer" message. There's also an "ignore" button hidden below a "more" button, but it in the end it lets you use it. But it doesn't always happen. [0]
It's not very user friendly, but it might be a bit more intuitive than apple's special dance of click right -> open to bypass said controls.
---
[0] For example, the Prometheus exporter for windows x64 is not signed and doesn't trigger the alert. I can download it (no alert) click open (no alert) and it runs . The x32 version does have a "this may damage your computer" alert in the browser (edge).
https://github.com/prometheus-community/windows_exporter/rel...