PRIAM CYBER AI · LONDON

Investigate,
then conclude
on evidence, not opinion.

AVA brings the discipline of a senior analyst to every alert. Hypothesis-driven triage, tested against your environment, ending in a verdict your team can defend — true positive, false positive, or a precise specification of what evidence is still missing. Forensic-grade. Audit-ready. Defensible by construction.

What it is
An Investigation Discipline for the SOC — autonomous L1 triage that closes alerts with a defensible verdict.
What it isn't
Not an alert summariser. Not an AI tool that fabricates certainty. Not a SOAR playbook in chat.
Who runs it
Enterprise SOCs and MSSP / MDR teams running cloud, on-prem, or private.
§POSITIONING · 01

Three categories.
One of them investigates.

The SOC market has spent a decade arguing about detection sensitivity and automation throughput. AVA is in a third category — the one most products skip — where evidence is gathered, hypotheses are tested, and a verdict gets made.

01 · Detection

Surfacing what looks anomalous.

SIEM and XDR rules surface events. Volume is the metric. False-positive density is the consequence. The decision is still pending.

02 · Automation

Executing pre-decided playbooks.

SOAR runs the steps an analyst already wrote. Speed is the metric. Coverage is bounded by the playbook library. Judgment is still pending.

03 · Investigation

Concluding on evidence.

AVA gathers evidence, tests hypotheses against your environment, and returns a verdict your team can defend. Discipline is the metric. The decision arrives with the alert.

Including a third verdict — INCONCLUSIVE — when the evidence won't support a conclusion: AVA says so, and names exactly what's missing.

Read the third verdict Where AVA lives
§THE ENGINE · 02

A verdict grounded in mathematics, not a well-phrased guess.

LLMs are built for conversation, not statistical truth — left alone, they talk themselves into false certainty. PEBRE splits the work: AVA's agents extract the evidence; PEBRE weighs it, the way forensic reasoning weighs competing explanations. The verdict is backed by measured evidence, with an audit trail you can trace.

§THE ARTIFACT · 03

The Investigation Report is the product.

Every alert produces one — the verdict, the evidence beneath it, the reasoning that connects them, the gaps that bound it.

INVESTIGATION REPORT PRM-2026-04-2841 · Northwind Energy · EU-WEST
TRUE POSITIVE

Suspicious PowerShell access to LSASS on a privileged endpoint.

  • RECEIVEDAlert received & normalised — Defender for Endpoint, sev. medium
  • EVIDENCE · EPEndpoint layer — process tree, command line, parent lineage captured
  • EVIDENCE · IDIdentity layer — recent sign-in geo, ASN, MFA posture asserted
  • VERDICTTRUE POSITIVE · evidence sufficient to conclude
§NUMBERS · 04

Numbers describe the discipline.
Evidence describes the verdict.

We don't quote inflated MTTR figures. Each number is labelled — observed in deployment, modelled, or an architectural commitment.

97%
False-positive closure
Observed in deployment — closed with a defensible Investigation Report, not auto-suppressed.
35–601–2
L1 triage · minutes
Observed in deployment — industry baseline → observed compression.
15024
L2 investigation · minutes
Observed in deployment — industry baseline → observed compression.
10×
Analyst throughput
Modelled — from L1+L2 compression. Methodology on request.
100%
Alert coverage
Commitment — every alert investigated, including the ones a queue would skip.
0
Unexplained actions
Commitment — every action in the audit trail resolves to evidence.
§INTEGRATIONS · 05

Native connectors into the stack you already run.

AVA reads from the systems your analysts already trust. No rip-and-replace, no new SIEM.

Microsoft Defender
XDR · Microsoft
CrowdStrike Falcon
EDR · CrowdStrike
Cortex XDR
XDR · Palo Alto
Microsoft Sentinel
SIEM · Microsoft
IBM QRadar
SIEM · IBM
Elastic Security
SIEM · Elastic
THE OFFER · 06

See AVA investigate your own alerts.

Every alert investigated, every investigation compounding. Send us one sanitised alert; we send back a full Investigation Report in 48 hours — verdict, evidence chain, audit trail, the report your team would defend.

What would you like?