This hasn't been enough of a problem for us to dive into as of yet.
Is the concern the emails being sent or the content of the file being shared (or both)?
Not sure how I'd approach this without diving in.
Because the file share emails don't come from your domain and would not have your headers in them from the source, I'm not sure how you could filter those effectively...
File shares, I know there are ways to prevent users from sharing documents. We use this for offboarding users in our district. I am unsure off the top of my head if this can be written in such a way that it would prevent outside domains from sharing with you.
I would strongly consider you have some internal conversations on what this would look like before doing anything with this...