Managed Detection and Response: AI Market Discovery Index
Tracking how AI platforms recommend managed detection and response. This public AI Market Discovery Index is updated monthly since July 2026.

On this page
- 01Benchmark Summary
- 02Current Benchmark at a Glance
- 03Research Scope and Qualification
- 04Current Brand Standings
- 05How to Read the Standings
- 06Recommendation Coverage Movement
- 07Largest Decline: CrowdStrike Falcon
- 08Largest Decline: Sophos Intercept X
- 09Category Leader: CrowdStrike Falcon
- 10Recommendation Placement Snapshot
- 11Buyer-Intent Distribution
- 12Historical Measurement Record
Benchmark Summary
CrowdStrike Falcon led the Managed Detection and Response benchmark with 56.3% valid recommendation coverage in September 2026, down from 66.0% in July 2026. The gap over the next closest brand, SentinelOne at 48.8%, narrowed to 7.5 points from 9.9 points in July 2026.
September 2026 was a month of significant movement, with four tracked brands declining beyond normal month-to-month variation. The largest coverage decline was CrowdStrike Falcon, which fell 15.1 points from 71.4% in August 2026 to 56.3% in September 2026. No tracked brand recorded a significant coverage increase; the largest rise was Secureworks Taegis, up 0.2 points from 1.5% in July 2026 to 1.7% in September 2026.
Across the full baseline-to-current series, Arctic Wolf, CrowdStrike Falcon, eSentire, SentinelOne, and Sophos Intercept X all moved downward beyond normal variation, with Arctic Wolf, eSentire, and Sophos Intercept X declining in each of the two months from July 2026 to September 2026. The benchmark began with 800 prompt-surface observations in each month and produced 467 qualified observations in September 2026 after qualification.
AI recommendation trend
valid recommendation coverage, Jul 2026 to Sep 2026
- CrowdStrike Falcon56.3%
- SentinelOne48.8%
- Sophos Intercept X33.8%
- Arctic Wolf16.9%
- Rapid7 InsightIDR8.3%
- Expel6.6%
- Red Canary6.6%
- eSentire3.6%
- Secureworks Taegis1.7%
- Deepwatch1.3%
Current Benchmark at a Glance
Measure | Jul 2026 | Sep 2026 | Movement |
|---|---|---|---|
Qualified benchmark observations | 326 | 467 | Up 141 |
Tracked brands | 10 | 10 | No change |
Qualified surface breadth | 6 | 6 | No change |
Recommendation-shaped answer share | 31.3% | 25.9% | Down 5.4 points |
Valid recommendation shortlist share | 64.7% | 58.0% | Down 6.7 points |
Leader by valid recommendation coverage | CrowdStrike Falcon | CrowdStrike Falcon | No change |
Qualified surface breadth counts the canonical AI/search surface families with at least one qualified observation: ChatGPT, Copilot, Gemini, Perplexity, AI Overviews, and AI Mode. Both months reached the maximum breadth of six. August 2026 also reached six families with 447 qualified observations between the two comparison months.
For the strategic interpretation of this benchmark, read CiteWorks Studio's analysis of How AI Search Is Recommending Managed Detection and Response
Research Scope and Qualification
The public benchmark is narrower than the raw collection universe by design. Brand-level percentages use the qualified observations as the public denominator, not the raw collection.
Want the full Authority Index
The paid deep-dive adds competitor threat profiles, the gap matrix, citation failure map, platform-by-platform recovery roadmap, and client-specific economic modeling.
Research stage | Jul 2026 | Sep 2026 | What it represents |
|---|---|---|---|
Source prompt-surface observations | 800 | 800 | Total collected prompts across surfaces |
Unique questions | 620 | 593 | Distinct questions after deduplication |
Brand / competitor mentions | 800 | 800 | Prompts mentioning at least one tracked brand |
Relevant observations | 366 | 569 | Prompts relevant to the vertical |
Irrelevant observations | 434 | 231 | Prompts not relevant to the vertical |
Qualified benchmark observations | 326 | 467 | Public benchmark denominator |
For full methodology, see AI Market Discovery Methodology.
Current Brand Standings
Brand | Presence rate | Valid recommendation coverage | Top-three rate | Rank-one rate | Net sentiment |
|---|---|---|---|---|---|
CrowdStrike Falcon | 94.4% | 56.3% | 48.8% | 36.2% | 0.823 |
SentinelOne | 85.2% | 48.8% | 37.3% | 2.8% | 0.802 |
Sophos Intercept X | 49.0% | 33.8% | 14.8% | 1.3% | 0.895 |
Arctic Wolf | 25.7% | 16.9% | 13.1% | 7.1% | 0.800 |
Rapid7 InsightIDR | 13.9% | 8.3% | 2.4% | 0.2% | 0.754 |
Expel | 10.1% | 6.6% | 2.4% | 0.2% | 0.830 |
Red Canary | 11.3% | 6.6% | 2.4% | 0.2% | 0.717 |
eSentire | 8.1% | 3.6% | 2.1% | 0.0% | 0.737 |
Secureworks Taegis | 4.9% | 1.7% | 0.4% | 0.0% | 0.739 |
Deepwatch | 1.7% | 1.3% | 0.0% | 0.0% | 0.875 |
How to Read the Standings
- Presence rate: share of qualified observations in which the brand is mentioned at all.
- Valid recommendation coverage: share of qualified observations in which the brand earns a valid recommendation.
- Top-three rate: share of qualified observations in which the brand appears in the top three recommended positions.
- Rank-one rate: share of qualified observations in which the brand is the first recommendation.
- Net sentiment: ratio of positive to total sentiment-bearing mentions, from 0 to 1.
For formulas and denominator rules, see AI Market Discovery Metric Definitions.
Recommendation Coverage Movement
Brand | Jul 2026 | Sep 2026 | Movement since baseline |
|---|---|---|---|
Arctic Wolf | 25.5% | 16.9% | Down 8.6 points |
CrowdStrike Falcon | 66.0% | 56.3% | Down 9.7 points |
Deepwatch | 1.5% | 1.3% | Down 0.2 points |
eSentire | 8.0% | 3.6% | Down 4.4 points |
Expel | 8.9% | 6.6% | Down 2.3 points |
Rapid7 InsightIDR | 11.0% | 8.3% | Down 2.7 points |
Red Canary | 9.8% | 6.6% | Down 3.2 points |
Secureworks Taegis | 1.5% | 1.7% | Up 0.2 points |
SentinelOne | 56.1% | 48.8% | Down 7.3 points |
Sophos Intercept X | 44.8% | 33.8% | Down 11.0 points |
September 2026 saw four brands decline beyond normal month-to-month variation on valid recommendation coverage. CrowdStrike Falcon fell 15.1 points from 71.4% in August 2026, SentinelOne fell 12.1 points from 60.9% in August 2026, Sophos Intercept X fell 6.9 points from 40.7% in August 2026, and Arctic Wolf fell 6.1 points from 23.0% in August 2026. The four-brand simultaneous decline suggests a category-wide shift rather than isolated brand issues. eSentire also declined from August to September 2026, down 2.2 points, which did not exceed its own month-to-month variation threshold but was significant across the full baseline-to-current series.
Largest Decline: CrowdStrike Falcon
CrowdStrike Falcon's valid recommendation coverage fell 15.1 points from 71.4% in August 2026 to 56.3% in September 2026, beyond normal variation. The brand's presence rate was effectively steady at 94.4%, meaning the decline came from recommendation conversion, not discoverability. Its top-three rate declined 8.9 points from 57.7% in July 2026 to 48.8% in September 2026, while rank-one rate declined 2.4 points from 38.6% to 36.2%.
Want the full Authority Index
The paid deep-dive adds competitor threat profiles, the gap matrix, citation failure map, platform-by-platform recovery roadmap, and client-specific economic modeling.
Largest Decline: Sophos Intercept X
Sophos Intercept X's valid recommendation coverage fell 11.0 points from 44.8% in July 2026 to 33.8% in September 2026, beyond normal variation. The brand declined in each of the two months in the series, showing a sustained downward pattern rather than a one-month fluctuation. Supporting metrics showed wider point movements: presence rate fell 10.8 points from 59.8% in July 2026 to 49.0% in September 2026, top-three rate fell 11.3 points from 26.1% to 14.8%, and rank-one rate fell 4.5 points from 5.8% to 1.3%, each beyond normal variation.
Category Leader: CrowdStrike Falcon
CrowdStrike Falcon remained the category leader for valid recommendation coverage at 56.3% in September 2026, down from 66.0% in July 2026. SentinelOne held second place at 48.8% in September 2026, down from 56.1% in July 2026. The leader's gap over SentinelOne narrowed from 9.9 points in July 2026 to 7.5 points in September 2026, even as both brands declined.
Recommendation Placement Snapshot
Coverage alone does not show how prominently a brand is recommended. The top two brands by valid recommendation coverage show different placement profiles. CrowdStrike Falcon led both top-three and rank-one rates in September 2026, while SentinelOne's 2.8% rank-one rate was markedly lower despite 48.8% coverage.
Brand | Sep 2026 top-three rate | Sep 2026 rank-one rate | Jul 2026 top-three rate | Jul 2026 rank-one rate |
|---|---|---|---|---|
CrowdStrike Falcon | 48.8% | 36.2% | 57.7% | 38.6% |
SentinelOne | 37.3% | 2.8% | 40.2% | 2.8% |
Arctic Wolf, at 16.9% valid recommendation coverage in September 2026, achieved a 7.1% rank-one rate, higher than SentinelOne's 2.8% despite less than half the coverage. Close coverage can still hide very different first-position rates.
Want the full Authority Index
The paid deep-dive adds competitor threat profiles, the gap matrix, citation failure map, platform-by-platform recovery roadmap, and client-specific economic modeling.
Buyer-Intent Distribution
All qualified observations in both months fell into the Brand Recommendation class, representing discovery and consideration intent.
Buyer-intent class | Jul 2026 | Sep 2026 |
|---|---|---|
Brand Recommendation | 326 | 467 |
Pricing & Value | 0 | 0 |
Multi-Brand Comparison | 0 | 0 |
Total qualified observations | 326 | 467 |
The current public series measures Brand Recommendation discovery and does not yet contain qualified observations in the Pricing & Value or Multi-Brand Comparison classes. Price, value, and head-to-head comparison questions therefore have no public signal in this data.
Historical Measurement Record
This is an evergreen benchmark URL. New measurements are added to the same report.
Measurement | Qualified observations | Coverage leader | Leader coverage | Largest coverage movement |
|---|---|---|---|---|
Jul 2026 | 326 | CrowdStrike Falcon | 66.0% | Baseline month |
Aug 2026 | 447 | CrowdStrike Falcon | 71.4% | Up 5.4 points by CrowdStrike Falcon |
Sep 2026 | 467 | CrowdStrike Falcon | 56.3% | Down 15.1 points by CrowdStrike Falcon |
Evidence and Source Layer
The benchmark is built from prompt-level observations that retain the query, AI/search surface, answer, brand outcome, recommendation placement, sentiment, and, where exposed, citations or attributable evidence sources. Source presence is evidence about the information environment. It is not automatically proof that the source caused the recommendation.
Scope Boundaries
This public benchmark does not measure:
- Market share or sales attribution
- Every possible AI response to a given query
- Organic-search ranking positions
- Social mention volume
- Private or sponsored channels
- Causality from a metric movement alone
One month of movement should not yet be treated as a trend until additional measurements confirm the direction.
About This Benchmark
The LLM Authority Index AI Market Discovery Index tracks how brands appear and are recommended across six canonical AI/search surface families: ChatGPT, Copilot, Gemini, Perplexity, AI Overviews, and AI Mode. It is a neutral industry benchmark; every brand is treated on its own terms.
- AI Market Discovery Methodology
- AI Market Discovery Metric Definitions
- AI Market Discovery Research Standards
- Modeled AI Authority Value
Get a Company-Level Authority Index
The public industry benchmark shows category-level standings. A company-level Authority Index can go deeper. The public percentage cannot identify the prompts, competitors, or sources causing the result.
Want the full Authority Index
The paid deep-dive adds competitor threat profiles, the gap matrix, citation failure map, platform-by-platform recovery roadmap, and client-specific economic modeling.
Keep reading
Related posts
Industry Reports
Endpoint Detection and Response Software: AI Market Discovery Index
Read this blog on LLM Authority Index.
ReadIndustry Reports
Vitamins and Dietary Supplements: AI Market Discovery Index
Read this blog on LLM Authority Index.
ReadIndustry Reports
VA Loans Lenders: AI Market Discovery Index
Read this blog on LLM Authority Index.
Read