Hypothesis-driven triage.
Every alert enters investigation with multiple competing Investigation Hypotheses — malicious and benign — drawn from MITRE ATT&CK and the alert's own context. AVA tests them. The one supported by evidence becomes the verdict.