Managed Detection and Response: AI Market Discovery Index

Tracking how AI platforms recommend managed detection and response. This public AI Market Discovery Index is updated monthly since July 2026.

Mark Huntley, J.D.
By Mark Huntley, J.D.Growth Strategist & AI Discovery Analyst
6 minutes read

Benchmark Summary

CrowdStrike Falcon led the Managed Detection and Response benchmark with 56.3% valid recommendation coverage in September 2026, down from 66.0% in July 2026. The gap over the next closest brand, SentinelOne at 48.8%, narrowed to 7.5 points from 9.9 points in July 2026.

September 2026 was a month of significant movement, with four tracked brands declining beyond normal month-to-month variation. The largest coverage decline was CrowdStrike Falcon, which fell 15.1 points from 71.4% in August 2026 to 56.3% in September 2026. No tracked brand recorded a significant coverage increase; the largest rise was Secureworks Taegis, up 0.2 points from 1.5% in July 2026 to 1.7% in September 2026.

Across the full baseline-to-current series, Arctic Wolf, CrowdStrike Falcon, eSentire, SentinelOne, and Sophos Intercept X all moved downward beyond normal variation, with Arctic Wolf, eSentire, and Sophos Intercept X declining in each of the two months from July 2026 to September 2026. The benchmark began with 800 prompt-surface observations in each month and produced 467 qualified observations in September 2026 after qualification.

AI recommendation trend

valid recommendation coverage, Jul 2026 to Sep 2026

0%20%40%60%80%Jul 2026Aug 2026Sep 2026
  • CrowdStrike Falcon56.3%
  • SentinelOne48.8%
  • Sophos Intercept X33.8%
  • Arctic Wolf16.9%
  • Rapid7 InsightIDR8.3%
  • Expel6.6%
  • Red Canary6.6%
  • eSentire3.6%
  • Secureworks Taegis1.7%
  • Deepwatch1.3%

Current Benchmark at a Glance

Measure

Jul 2026

Sep 2026

Movement

Qualified benchmark observations

326

467

Up 141

Tracked brands

10

10

No change

Qualified surface breadth

6

6

No change

Recommendation-shaped answer share

31.3%

25.9%

Down 5.4 points

Valid recommendation shortlist share

64.7%

58.0%

Down 6.7 points

Leader by valid recommendation coverage

CrowdStrike Falcon

CrowdStrike Falcon

No change

Qualified surface breadth counts the canonical AI/search surface families with at least one qualified observation: ChatGPT, Copilot, Gemini, Perplexity, AI Overviews, and AI Mode. Both months reached the maximum breadth of six. August 2026 also reached six families with 447 qualified observations between the two comparison months.

For the strategic interpretation of this benchmark, read CiteWorks Studio's analysis of How AI Search Is Recommending Managed Detection and Response

Research Scope and Qualification

The public benchmark is narrower than the raw collection universe by design. Brand-level percentages use the qualified observations as the public denominator, not the raw collection.

Want the full Authority Index

The paid deep-dive adds competitor threat profiles, the gap matrix, citation failure map, platform-by-platform recovery roadmap, and client-specific economic modeling.

Research stage

Jul 2026

Sep 2026

What it represents

Source prompt-surface observations

800

800

Total collected prompts across surfaces

Unique questions

620

593

Distinct questions after deduplication

Brand / competitor mentions

800

800

Prompts mentioning at least one tracked brand

Relevant observations

366

569

Prompts relevant to the vertical

Irrelevant observations

434

231

Prompts not relevant to the vertical

Qualified benchmark observations

326

467

Public benchmark denominator

For full methodology, see AI Market Discovery Methodology.

Current Brand Standings

Brand

Presence rate

Valid recommendation coverage

Top-three rate

Rank-one rate

Net sentiment

CrowdStrike Falcon

94.4%

56.3%

48.8%

36.2%

0.823

SentinelOne

85.2%

48.8%

37.3%

2.8%

0.802

Sophos Intercept X

49.0%

33.8%

14.8%

1.3%

0.895

Arctic Wolf

25.7%

16.9%

13.1%

7.1%

0.800

Rapid7 InsightIDR

13.9%

8.3%

2.4%

0.2%

0.754

Expel

10.1%

6.6%

2.4%

0.2%

0.830

Red Canary

11.3%

6.6%

2.4%

0.2%

0.717

eSentire

8.1%

3.6%

2.1%

0.0%

0.737

Secureworks Taegis

4.9%

1.7%

0.4%

0.0%

0.739

Deepwatch

1.7%

1.3%

0.0%

0.0%

0.875

How to Read the Standings

  • Presence rate: share of qualified observations in which the brand is mentioned at all.
  • Valid recommendation coverage: share of qualified observations in which the brand earns a valid recommendation.
  • Top-three rate: share of qualified observations in which the brand appears in the top three recommended positions.
  • Rank-one rate: share of qualified observations in which the brand is the first recommendation.
  • Net sentiment: ratio of positive to total sentiment-bearing mentions, from 0 to 1.

For formulas and denominator rules, see AI Market Discovery Metric Definitions.

Recommendation Coverage Movement

Brand

Jul 2026

Sep 2026

Movement since baseline

Arctic Wolf

25.5%

16.9%

Down 8.6 points

CrowdStrike Falcon

66.0%

56.3%

Down 9.7 points

Deepwatch

1.5%

1.3%

Down 0.2 points

eSentire

8.0%

3.6%

Down 4.4 points

Expel

8.9%

6.6%

Down 2.3 points

Rapid7 InsightIDR

11.0%

8.3%

Down 2.7 points

Red Canary

9.8%

6.6%

Down 3.2 points

Secureworks Taegis

1.5%

1.7%

Up 0.2 points

SentinelOne

56.1%

48.8%

Down 7.3 points

Sophos Intercept X

44.8%

33.8%

Down 11.0 points

September 2026 saw four brands decline beyond normal month-to-month variation on valid recommendation coverage. CrowdStrike Falcon fell 15.1 points from 71.4% in August 2026, SentinelOne fell 12.1 points from 60.9% in August 2026, Sophos Intercept X fell 6.9 points from 40.7% in August 2026, and Arctic Wolf fell 6.1 points from 23.0% in August 2026. The four-brand simultaneous decline suggests a category-wide shift rather than isolated brand issues. eSentire also declined from August to September 2026, down 2.2 points, which did not exceed its own month-to-month variation threshold but was significant across the full baseline-to-current series.

Largest Decline: CrowdStrike Falcon

CrowdStrike Falcon's valid recommendation coverage fell 15.1 points from 71.4% in August 2026 to 56.3% in September 2026, beyond normal variation. The brand's presence rate was effectively steady at 94.4%, meaning the decline came from recommendation conversion, not discoverability. Its top-three rate declined 8.9 points from 57.7% in July 2026 to 48.8% in September 2026, while rank-one rate declined 2.4 points from 38.6% to 36.2%.

Want the full Authority Index

The paid deep-dive adds competitor threat profiles, the gap matrix, citation failure map, platform-by-platform recovery roadmap, and client-specific economic modeling.

Largest Decline: Sophos Intercept X

Sophos Intercept X's valid recommendation coverage fell 11.0 points from 44.8% in July 2026 to 33.8% in September 2026, beyond normal variation. The brand declined in each of the two months in the series, showing a sustained downward pattern rather than a one-month fluctuation. Supporting metrics showed wider point movements: presence rate fell 10.8 points from 59.8% in July 2026 to 49.0% in September 2026, top-three rate fell 11.3 points from 26.1% to 14.8%, and rank-one rate fell 4.5 points from 5.8% to 1.3%, each beyond normal variation.

Category Leader: CrowdStrike Falcon

CrowdStrike Falcon remained the category leader for valid recommendation coverage at 56.3% in September 2026, down from 66.0% in July 2026. SentinelOne held second place at 48.8% in September 2026, down from 56.1% in July 2026. The leader's gap over SentinelOne narrowed from 9.9 points in July 2026 to 7.5 points in September 2026, even as both brands declined.

Recommendation Placement Snapshot

Coverage alone does not show how prominently a brand is recommended. The top two brands by valid recommendation coverage show different placement profiles. CrowdStrike Falcon led both top-three and rank-one rates in September 2026, while SentinelOne's 2.8% rank-one rate was markedly lower despite 48.8% coverage.

Brand

Sep 2026 top-three rate

Sep 2026 rank-one rate

Jul 2026 top-three rate

Jul 2026 rank-one rate

CrowdStrike Falcon

48.8%

36.2%

57.7%

38.6%

SentinelOne

37.3%

2.8%

40.2%

2.8%

Arctic Wolf, at 16.9% valid recommendation coverage in September 2026, achieved a 7.1% rank-one rate, higher than SentinelOne's 2.8% despite less than half the coverage. Close coverage can still hide very different first-position rates.

Want the full Authority Index

The paid deep-dive adds competitor threat profiles, the gap matrix, citation failure map, platform-by-platform recovery roadmap, and client-specific economic modeling.

Buyer-Intent Distribution

All qualified observations in both months fell into the Brand Recommendation class, representing discovery and consideration intent.

Buyer-intent class

Jul 2026

Sep 2026

Brand Recommendation

326

467

Pricing & Value

0

0

Multi-Brand Comparison

0

0

Total qualified observations

326

467

The current public series measures Brand Recommendation discovery and does not yet contain qualified observations in the Pricing & Value or Multi-Brand Comparison classes. Price, value, and head-to-head comparison questions therefore have no public signal in this data.

Historical Measurement Record

This is an evergreen benchmark URL. New measurements are added to the same report.

Measurement

Qualified observations

Coverage leader

Leader coverage

Largest coverage movement

Jul 2026

326

CrowdStrike Falcon

66.0%

Baseline month

Aug 2026

447

CrowdStrike Falcon

71.4%

Up 5.4 points by CrowdStrike Falcon

Sep 2026

467

CrowdStrike Falcon

56.3%

Down 15.1 points by CrowdStrike Falcon

Evidence and Source Layer

The benchmark is built from prompt-level observations that retain the query, AI/search surface, answer, brand outcome, recommendation placement, sentiment, and, where exposed, citations or attributable evidence sources. Source presence is evidence about the information environment. It is not automatically proof that the source caused the recommendation.

Scope Boundaries

This public benchmark does not measure:

  • Market share or sales attribution
  • Every possible AI response to a given query
  • Organic-search ranking positions
  • Social mention volume
  • Private or sponsored channels
  • Causality from a metric movement alone

One month of movement should not yet be treated as a trend until additional measurements confirm the direction.

About This Benchmark

The LLM Authority Index AI Market Discovery Index tracks how brands appear and are recommended across six canonical AI/search surface families: ChatGPT, Copilot, Gemini, Perplexity, AI Overviews, and AI Mode. It is a neutral industry benchmark; every brand is treated on its own terms.

Get a Company-Level Authority Index

The public industry benchmark shows category-level standings. A company-level Authority Index can go deeper. The public percentage cannot identify the prompts, competitors, or sources causing the result.

Get my free AI Company Index

Want the full Authority Index

The paid deep-dive adds competitor threat profiles, the gap matrix, citation failure map, platform-by-platform recovery roadmap, and client-specific economic modeling.