Managed Detection and Response: AI Market Discovery Index

Tracking how AI platforms recommend managed detection and response. This public AI Market Discovery Index is updated monthly since July 2026.

Mark Huntley, J.D.
By Mark Huntley, J.D.Growth Strategist & AI Discovery Analyst
6 minutes read

Benchmark Summary

CrowdStrike Falcon led the Managed Detection and Response benchmark with 71.4% valid recommendation coverage in August 2026, up from 66.0% in July 2026. The gap over the next closest brand, SentinelOne at 60.9% in August 2026, widened to 10.5 points from 9.9 points in July 2026.

No tracked brand moved beyond normal month-to-month variation in August 2026. The largest coverage increase was CrowdStrike Falcon, which rose 5.4 points from 66.0% in July 2026 to 71.4% in August 2026. The largest coverage decline was Sophos Intercept X, which fell 4.1 points from 44.8% in July 2026 to 40.7% in August 2026.

Since the baseline month of July 2026, CrowdStrike Falcon, Rapid7 InsightIDR, Secureworks Taegis, and SentinelOne have moved upward on valid recommendation coverage, while Arctic Wolf, Deepwatch, eSentire, Expel, Red Canary, and Sophos Intercept X have moved downward, all within normal variation. The benchmark began with 800 prompt-surface observations in each month and produced 447 qualified observations in August 2026 after qualification.

AI recommendation trend

valid recommendation coverage, Jul 2026 to Aug 2026

  • CrowdStrike Falcon+5.4%
    Jul 202666.0%
    Aug 202671.4%
  • SentinelOne+4.8%
    Jul 202656.1%
    Aug 202660.9%
  • Sophos Intercept X-4.1%
    Jul 202644.8%
    Aug 202640.7%
  • Arctic Wolf-2.5%
    Jul 202625.5%
    Aug 202623.0%
  • Rapid7 InsightIDR+1.1%
    Jul 202611.0%
    Aug 202612.1%
  • Red Canary-1.7%
    Jul 20269.8%
    Aug 20268.1%
  • Expel-2.2%
    Jul 20268.9%
    Aug 20266.7%
  • eSentire-2.2%
    Jul 20268.0%
    Aug 20265.8%
  • Secureworks Taegis+1.9%
    Jul 20261.5%
    Aug 20263.4%
  • Deepwatch-0.4%
    Jul 20261.5%
    Aug 20261.1%

Current Benchmark at a Glance

Measure

Jul 2026

Aug 2026

Movement

Qualified benchmark observations

326

447

Up 121

Tracked brands

10

10

No change

Qualified surface breadth

6

6

No change

Recommendation-shaped answer share

31.3%

34.9%

Up 3.6 points

Valid recommendation shortlist share

64.7%

60.0%

Down 4.7 points

Leader by valid recommendation coverage

CrowdStrike Falcon

CrowdStrike Falcon

No change

Qualified surface breadth counts the canonical AI/search surface families with at least one qualified observation: ChatGPT, Copilot, Gemini, Perplexity, AI Overviews, and AI Mode. Both months reached the maximum breadth of six.

For the strategic interpretation of this benchmark, read CiteWorks Studio's analysis of How AI Search Is Recommending Managed Detection and Response

Research Scope and Qualification

The public benchmark is narrower than the raw collection universe by design. Brand-level percentages use the qualified observations as the public denominator, not the raw collection.

Research stage

Jul 2026

Aug 2026

What it represents

Source prompt-surface observations

800

800

Total collected prompts across surfaces

Unique questions

620

602

Distinct questions after deduplication

Brand / competitor mentions

800

800

Prompts mentioning at least one tracked brand

Relevant observations

366

519

Prompts relevant to the vertical

Irrelevant observations

434

281

Prompts not relevant to the vertical

Qualified benchmark observations

326

447

Public benchmark denominator

Want the full Authority Index

The paid deep-dive adds competitor threat profiles, the gap matrix, citation failure map, platform-by-platform recovery roadmap, and client-specific economic modeling.

For full methodology, see AI Market Discovery Methodology.

Current Brand Standings

Brand

Presence rate

Valid recommendation coverage

Top-three rate

Rank-one rate

Net sentiment

CrowdStrike Falcon

95.5%

71.4%

51.2%

33.6%

0.815

SentinelOne

83.0%

60.9%

36.9%

2.5%

0.803

Sophos Intercept X

49.2%

40.7%

16.1%

2.2%

0.868

Arctic Wolf

27.5%

23.0%

13.9%

8.1%

0.862

Rapid7 InsightIDR

15.4%

12.1%

3.8%

0.0%

0.826

Red Canary

9.2%

8.1%

1.8%

0.2%

0.902

eSentire

8.1%

5.8%

1.6%

0.2%

0.806

Expel

7.4%

6.7%

2.2%

0.2%

0.909

Secureworks Taegis

3.8%

3.4%

0.7%

0.2%

0.941

Deepwatch

1.6%

1.1%

0.0%

0.0%

0.857

How to Read the Standings

  • Presence rate: share of qualified observations in which the brand is mentioned at all.
  • Valid recommendation coverage: share of qualified observations in which the brand earns a valid recommendation.
  • Top-three rate: share of qualified observations in which the brand appears in the top three recommended positions.
  • Rank-one rate: share of qualified observations in which the brand is the first recommendation.
  • Net sentiment: ratio of positive to total sentiment-bearing mentions, from 0 to 1.

For formulas and denominator rules, see AI Market Discovery Metric Definitions.

Recommendation Coverage Movement

Brand

Jul 2026

Aug 2026

Movement since baseline

Arctic Wolf

25.5%

23.0%

Down 2.5 points

CrowdStrike Falcon

66.0%

71.4%

Up 5.4 points

Deepwatch

1.5%

1.1%

Down 0.4 points

eSentire

8.0%

5.8%

Down 2.2 points

Expel

8.9%

6.7%

Down 2.2 points

Rapid7 InsightIDR

11.0%

12.1%

Up 1.1 points

Red Canary

9.8%

8.1%

Down 1.7 points

Secureworks Taegis

1.5%

3.4%

Up 1.9 points

SentinelOne

56.1%

60.9%

Up 4.8 points

Sophos Intercept X

44.8%

40.7%

Down 4.1 points

August 2026 was a quiet month for the Managed Detection and Response benchmark. No brand moved beyond normal month-to-month variation on valid recommendation coverage. All ten tracked brands are classified as stable.

A closer look at supporting metrics shows Sophos Intercept X declined across all three secondary signals in August 2026: presence rate fell 10.6 points from 59.8% in July 2026 to 49.2% in August 2026, top-three rate fell 10.0 points from 26.1% to 16.1%, and rank-one rate fell 3.6 points from 5.8% to 2.2%. The primary coverage measure moved a smaller 4.1 points and is classified as stable.

Largest Increase: CrowdStrike Falcon

CrowdStrike Falcon's valid recommendation coverage rose 5.4 points from 66.0% in July 2026 to 71.4% in August 2026, within normal variation. The brand's presence rate was effectively steady at 95.5% in August 2026, down 1.4 points from 96.9% in July 2026. Its top-three rate declined 6.5 points and its rank-one rate declined 5.0 points despite higher coverage.

Want the full Authority Index

The paid deep-dive adds competitor threat profiles, the gap matrix, citation failure map, platform-by-platform recovery roadmap, and client-specific economic modeling.

Largest Decline: Sophos Intercept X

Sophos Intercept X's valid recommendation coverage fell 4.1 points from 44.8% in July 2026 to 40.7% in August 2026, within normal variation. Supporting metrics showed much larger point movements, including a 10.6-point presence decline.

Category Leader: CrowdStrike Falcon

CrowdStrike Falcon remained the category leader for valid recommendation coverage at 71.4% in August 2026, up from 66.0% in July 2026. SentinelOne held second place at 60.9% in August 2026, up from 56.1% in July 2026. The leader's gap over SentinelOne widened from 9.9 points in July 2026 to 10.5 points in August 2026.

Recommendation Placement Snapshot

Coverage alone does not show how prominently a brand is recommended. The top two brands by valid recommendation coverage show different placement profiles. CrowdStrike Falcon led both top-three and rank-one rates in August 2026, while SentinelOne's rank-one rate was markedly lower despite high coverage.

Brand

Aug 2026 top-three rate

Aug 2026 rank-one rate

Jul 2026 top-three rate

Jul 2026 rank-one rate

CrowdStrike Falcon

51.2%

33.6%

57.7%

38.6%

SentinelOne

36.9%

2.5%

40.2%

2.8%

Arctic Wolf, at 23.0% valid recommendation coverage in August 2026, achieved an 8.1% rank-one rate, higher than SentinelOne's 2.5% despite less than half the coverage. Close coverage can still hide very different first-position rates.

Buyer-Intent Distribution

All qualified observations in both months fell into the Brand Recommendation class, representing discovery and consideration intent.

Buyer-intent class

Jul 2026

Aug 2026

Brand Recommendation

326

447

Pricing & Value

0

0

Multi-Brand Comparison

0

0

Total qualified observations

326

447

The current public series measures Brand Recommendation discovery and does not yet contain qualified observations in the Pricing & Value or Multi-Brand Comparison classes.

Historical Measurement Record

This is an evergreen benchmark URL. New measurements are added to the same report.

Measurement

Qualified observations

Coverage leader

Leader coverage

Largest coverage movement

Jul 2026

326

CrowdStrike Falcon

66.0%

44.8% to 25.5% move by Sophos Intercept X and Arctic Wolf (baseline)

Aug 2026

447

CrowdStrike Falcon

71.4%

Up 5.4 points by CrowdStrike Falcon

Evidence and Source Layer

The benchmark is built from prompt-level observations that retain the query, AI/search surface, answer, brand outcome, recommendation placement, sentiment, and, where exposed, citations or attributable evidence sources. Source presence is evidence about the information environment. It is not automatically proof that the source caused the recommendation.

Scope Boundaries

This public benchmark does not measure:

  • Market share or sales attribution
  • Every possible AI response to a given query
  • Organic-search ranking positions
  • Social mention volume
  • Private or sponsored channels
  • Causality from a metric movement alone

About This Benchmark

The LLM Authority Index AI Market Discovery Index tracks how brands appear and are recommended across six canonical AI/search surface families: ChatGPT, Copilot, Gemini, Perplexity, AI Overviews, and AI Mode. It is a neutral industry benchmark; every brand is treated on its own terms.

Get a Company-Level Authority Index

The public industry benchmark shows category-level standings. A company-level Authority Index can go deeper.

Get my free AI Company Index

Want the full Authority Index

The paid deep-dive adds competitor threat profiles, the gap matrix, citation failure map, platform-by-platform recovery roadmap, and client-specific economic modeling.