Unauthorized Machine Learning Model Access Attempts

This rule detects multiple unauthorized access attempts to files identified as machine learning models, weights, or checkpoints. It specifically looks for Security Event ID 4656 (Auditing of object access) where the object name contains keywords like 'model', 'weights', or 'checkpoint', and the access mask indicates unauthorized access attempts (0x0001 for ReadData or ListDirectory, 0x0002 for WriteData or AddFile). The rule then summarizes these attempts by user, computer, and hour, triggering an alert if 5 or more attempts are made within an hour.