Managed Detection and Response: AI Market Discovery Index
Tracking how AI platforms recommend managed detection and response. This public AI Market Discovery Index is updated monthly since July 2026.

On this page
- 01Benchmark Summary
- 02Current Benchmark at a Glance
- 03Research Scope and Qualification
- 04Current Brand Standings
- 05How to Read the Standings
- 06Recommendation Coverage Movement
- 07Largest Increase: CrowdStrike Falcon
- 08Largest Decline: Sophos Intercept X
- 09Category Leader: CrowdStrike Falcon
- 10Recommendation Placement Snapshot
- 11Buyer-Intent Distribution
- 12Historical Measurement Record
Benchmark Summary
CrowdStrike Falcon led the Managed Detection and Response benchmark with 71.4% valid recommendation coverage in August 2026, up from 66.0% in July 2026. The gap over the next closest brand, SentinelOne at 60.9% in August 2026, widened to 10.5 points from 9.9 points in July 2026.
No tracked brand moved beyond normal month-to-month variation in August 2026. The largest coverage increase was CrowdStrike Falcon, which rose 5.4 points from 66.0% in July 2026 to 71.4% in August 2026. The largest coverage decline was Sophos Intercept X, which fell 4.1 points from 44.8% in July 2026 to 40.7% in August 2026.
Since the baseline month of July 2026, CrowdStrike Falcon, Rapid7 InsightIDR, Secureworks Taegis, and SentinelOne have moved upward on valid recommendation coverage, while Arctic Wolf, Deepwatch, eSentire, Expel, Red Canary, and Sophos Intercept X have moved downward, all within normal variation. The benchmark began with 800 prompt-surface observations in each month and produced 447 qualified observations in August 2026 after qualification.
AI recommendation trend
valid recommendation coverage, Jul 2026 to Aug 2026
- CrowdStrike Falcon+5.4%Jul 202666.0%Aug 202671.4%
- SentinelOne+4.8%Jul 202656.1%Aug 202660.9%
- Sophos Intercept X-4.1%Jul 202644.8%Aug 202640.7%
- Arctic Wolf-2.5%Jul 202625.5%Aug 202623.0%
- Rapid7 InsightIDR+1.1%Jul 202611.0%Aug 202612.1%
- Red Canary-1.7%Jul 20269.8%Aug 20268.1%
- Expel-2.2%Jul 20268.9%Aug 20266.7%
- eSentire-2.2%Jul 20268.0%Aug 20265.8%
- Secureworks Taegis+1.9%Jul 20261.5%Aug 20263.4%
- Deepwatch-0.4%Jul 20261.5%Aug 20261.1%
Current Benchmark at a Glance
Measure | Jul 2026 | Aug 2026 | Movement |
|---|---|---|---|
Qualified benchmark observations | 326 | 447 | Up 121 |
Tracked brands | 10 | 10 | No change |
Qualified surface breadth | 6 | 6 | No change |
Recommendation-shaped answer share | 31.3% | 34.9% | Up 3.6 points |
Valid recommendation shortlist share | 64.7% | 60.0% | Down 4.7 points |
Leader by valid recommendation coverage | CrowdStrike Falcon | CrowdStrike Falcon | No change |
Qualified surface breadth counts the canonical AI/search surface families with at least one qualified observation: ChatGPT, Copilot, Gemini, Perplexity, AI Overviews, and AI Mode. Both months reached the maximum breadth of six.
For the strategic interpretation of this benchmark, read CiteWorks Studio's analysis of How AI Search Is Recommending Managed Detection and Response
Research Scope and Qualification
The public benchmark is narrower than the raw collection universe by design. Brand-level percentages use the qualified observations as the public denominator, not the raw collection.
Research stage | Jul 2026 | Aug 2026 | What it represents |
|---|---|---|---|
Source prompt-surface observations | 800 | 800 | Total collected prompts across surfaces |
Unique questions | 620 | 602 | Distinct questions after deduplication |
Brand / competitor mentions | 800 | 800 | Prompts mentioning at least one tracked brand |
Relevant observations | 366 | 519 | Prompts relevant to the vertical |
Irrelevant observations | 434 | 281 | Prompts not relevant to the vertical |
Qualified benchmark observations | 326 | 447 | Public benchmark denominator |
Want the full Authority Index
The paid deep-dive adds competitor threat profiles, the gap matrix, citation failure map, platform-by-platform recovery roadmap, and client-specific economic modeling.
For full methodology, see AI Market Discovery Methodology.
Current Brand Standings
Brand | Presence rate | Valid recommendation coverage | Top-three rate | Rank-one rate | Net sentiment |
|---|---|---|---|---|---|
CrowdStrike Falcon | 95.5% | 71.4% | 51.2% | 33.6% | 0.815 |
SentinelOne | 83.0% | 60.9% | 36.9% | 2.5% | 0.803 |
Sophos Intercept X | 49.2% | 40.7% | 16.1% | 2.2% | 0.868 |
Arctic Wolf | 27.5% | 23.0% | 13.9% | 8.1% | 0.862 |
Rapid7 InsightIDR | 15.4% | 12.1% | 3.8% | 0.0% | 0.826 |
Red Canary | 9.2% | 8.1% | 1.8% | 0.2% | 0.902 |
eSentire | 8.1% | 5.8% | 1.6% | 0.2% | 0.806 |
Expel | 7.4% | 6.7% | 2.2% | 0.2% | 0.909 |
Secureworks Taegis | 3.8% | 3.4% | 0.7% | 0.2% | 0.941 |
Deepwatch | 1.6% | 1.1% | 0.0% | 0.0% | 0.857 |
How to Read the Standings
- Presence rate: share of qualified observations in which the brand is mentioned at all.
- Valid recommendation coverage: share of qualified observations in which the brand earns a valid recommendation.
- Top-three rate: share of qualified observations in which the brand appears in the top three recommended positions.
- Rank-one rate: share of qualified observations in which the brand is the first recommendation.
- Net sentiment: ratio of positive to total sentiment-bearing mentions, from 0 to 1.
For formulas and denominator rules, see AI Market Discovery Metric Definitions.
Recommendation Coverage Movement
Brand | Jul 2026 | Aug 2026 | Movement since baseline |
|---|---|---|---|
Arctic Wolf | 25.5% | 23.0% | Down 2.5 points |
CrowdStrike Falcon | 66.0% | 71.4% | Up 5.4 points |
Deepwatch | 1.5% | 1.1% | Down 0.4 points |
eSentire | 8.0% | 5.8% | Down 2.2 points |
Expel | 8.9% | 6.7% | Down 2.2 points |
Rapid7 InsightIDR | 11.0% | 12.1% | Up 1.1 points |
Red Canary | 9.8% | 8.1% | Down 1.7 points |
Secureworks Taegis | 1.5% | 3.4% | Up 1.9 points |
SentinelOne | 56.1% | 60.9% | Up 4.8 points |
Sophos Intercept X | 44.8% | 40.7% | Down 4.1 points |
August 2026 was a quiet month for the Managed Detection and Response benchmark. No brand moved beyond normal month-to-month variation on valid recommendation coverage. All ten tracked brands are classified as stable.
A closer look at supporting metrics shows Sophos Intercept X declined across all three secondary signals in August 2026: presence rate fell 10.6 points from 59.8% in July 2026 to 49.2% in August 2026, top-three rate fell 10.0 points from 26.1% to 16.1%, and rank-one rate fell 3.6 points from 5.8% to 2.2%. The primary coverage measure moved a smaller 4.1 points and is classified as stable.
Largest Increase: CrowdStrike Falcon
CrowdStrike Falcon's valid recommendation coverage rose 5.4 points from 66.0% in July 2026 to 71.4% in August 2026, within normal variation. The brand's presence rate was effectively steady at 95.5% in August 2026, down 1.4 points from 96.9% in July 2026. Its top-three rate declined 6.5 points and its rank-one rate declined 5.0 points despite higher coverage.
Want the full Authority Index
The paid deep-dive adds competitor threat profiles, the gap matrix, citation failure map, platform-by-platform recovery roadmap, and client-specific economic modeling.
Largest Decline: Sophos Intercept X
Sophos Intercept X's valid recommendation coverage fell 4.1 points from 44.8% in July 2026 to 40.7% in August 2026, within normal variation. Supporting metrics showed much larger point movements, including a 10.6-point presence decline.
Category Leader: CrowdStrike Falcon
CrowdStrike Falcon remained the category leader for valid recommendation coverage at 71.4% in August 2026, up from 66.0% in July 2026. SentinelOne held second place at 60.9% in August 2026, up from 56.1% in July 2026. The leader's gap over SentinelOne widened from 9.9 points in July 2026 to 10.5 points in August 2026.
Recommendation Placement Snapshot
Coverage alone does not show how prominently a brand is recommended. The top two brands by valid recommendation coverage show different placement profiles. CrowdStrike Falcon led both top-three and rank-one rates in August 2026, while SentinelOne's rank-one rate was markedly lower despite high coverage.
Brand | Aug 2026 top-three rate | Aug 2026 rank-one rate | Jul 2026 top-three rate | Jul 2026 rank-one rate |
|---|---|---|---|---|
CrowdStrike Falcon | 51.2% | 33.6% | 57.7% | 38.6% |
SentinelOne | 36.9% | 2.5% | 40.2% | 2.8% |
Arctic Wolf, at 23.0% valid recommendation coverage in August 2026, achieved an 8.1% rank-one rate, higher than SentinelOne's 2.5% despite less than half the coverage. Close coverage can still hide very different first-position rates.
Buyer-Intent Distribution
All qualified observations in both months fell into the Brand Recommendation class, representing discovery and consideration intent.
Buyer-intent class | Jul 2026 | Aug 2026 |
|---|---|---|
Brand Recommendation | 326 | 447 |
Pricing & Value | 0 | 0 |
Multi-Brand Comparison | 0 | 0 |
Total qualified observations | 326 | 447 |
The current public series measures Brand Recommendation discovery and does not yet contain qualified observations in the Pricing & Value or Multi-Brand Comparison classes.
Historical Measurement Record
This is an evergreen benchmark URL. New measurements are added to the same report.
Measurement | Qualified observations | Coverage leader | Leader coverage | Largest coverage movement |
|---|---|---|---|---|
Jul 2026 | 326 | CrowdStrike Falcon | 66.0% | 44.8% to 25.5% move by Sophos Intercept X and Arctic Wolf (baseline) |
Aug 2026 | 447 | CrowdStrike Falcon | 71.4% | Up 5.4 points by CrowdStrike Falcon |
Evidence and Source Layer
The benchmark is built from prompt-level observations that retain the query, AI/search surface, answer, brand outcome, recommendation placement, sentiment, and, where exposed, citations or attributable evidence sources. Source presence is evidence about the information environment. It is not automatically proof that the source caused the recommendation.
Scope Boundaries
This public benchmark does not measure:
- Market share or sales attribution
- Every possible AI response to a given query
- Organic-search ranking positions
- Social mention volume
- Private or sponsored channels
- Causality from a metric movement alone
About This Benchmark
The LLM Authority Index AI Market Discovery Index tracks how brands appear and are recommended across six canonical AI/search surface families: ChatGPT, Copilot, Gemini, Perplexity, AI Overviews, and AI Mode. It is a neutral industry benchmark; every brand is treated on its own terms.
- AI Market Discovery Methodology
- AI Market Discovery Metric Definitions
- AI Market Discovery Research Standards
- Modeled AI Authority Value
Get a Company-Level Authority Index
The public industry benchmark shows category-level standings. A company-level Authority Index can go deeper.
Want the full Authority Index
The paid deep-dive adds competitor threat profiles, the gap matrix, citation failure map, platform-by-platform recovery roadmap, and client-specific economic modeling.
Keep reading
Related posts
Industry Reports
Endpoint Detection and Response Software: AI Market Discovery Index
Read this blog on LLM Authority Index.
ReadIndustry Reports
Revenue Cycle Management: AI Market Discovery Index
Read this blog on LLM Authority Index.
ReadIndustry Reports
Mental Health Treatment Centers: AI Market Discovery Index
Read this blog on LLM Authority Index.
Read