How AI Search Is Recommending Managed Detection and Response: Monthly Trends
This analysis is based on the source benchmark: Managed Detection and Response: 2026 AI Market Discovery Index
Key Takeaways
- CrowdStrike Falcon remained the recommendation leader at 56.3%, but its lead over SentinelOne narrowed to 7.5 points after a sharp month-over-month decline.
- Five tracked brands posted significant declines in September 2026, with no brand recording a significant increase.
- The category's upper tier compressed from July to September as CrowdStrike Falcon, SentinelOne, Sophos Intercept X, Arctic Wolf, and eSentire all lost recommendation coverage.
- Qualified observations increased from 326 in July to 467 in September, even as recommendation-shaped answers and valid shortlist share both declined.
Executive Summary
CrowdStrike Falcon remains the coverage leader in AI-driven recommendations for Managed Detection and Response, but its lead narrowed sharply in September 2026. The benchmark shows CrowdStrike Falcon at 56.3% valid recommendation coverage, down 15.1 points from 71.4% in August. The gap to second-place SentinelOne narrowed to 7.5 points, with SentinelOne at 48.8% coverage after its own 12.1-point decline. Five of ten tracked brands are classified as significant decliners this period: Arctic Wolf, CrowdStrike Falcon, SentinelOne, and Sophos Intercept X each crossed the month-over-month significance threshold, while eSentire's decline is significant against the baseline with a two-month downward streak. No brand posted a significant increase.
Across the July-to-September baseline, the category's upper tier compressed notably. CrowdStrike Falcon is down 9.7 points from 66.0% in July, SentinelOne is down 7.3 points from 56.1%, and Sophos Intercept X fell 11.0 points from 44.8% to 33.8%. Arctic Wolf declined 8.6 points from 25.5% to 16.9%, and eSentire dropped 4.4 points from 8.0% to 3.6%. No tracked brand recorded a significant upward move this month.
This benchmark's July run began from 800 prompt-surface observations (620 unique questions); the September run began from 800 prompt-surface observations (593 unique questions). In both months, all 800 observations mentioned a tracked brand or competitor. Relevance filtering left 366 relevant and 434 irrelevant prompts in July, and 569 relevant and 231 irrelevant prompts in September. The public brand-level metrics are calculated from the 326 qualified observations in July and 467 qualified observations in September that survived both qualification stages.
AI recommendation trend
valid recommendation coverage, Jul 2026 to Sep 2026
- CrowdStrike Falcon56.3%
- SentinelOne48.8%
- Sophos Intercept X33.8%
- Arctic Wolf16.9%
- Rapid7 InsightIDR8.3%
- Expel6.6%
- Red Canary6.6%
- eSentire3.6%
- Secureworks Taegis1.7%
- Deepwatch1.3%
Key Findings
Signal | September 2026 finding |
|---|---|
Category status | Significant movement; five tracked brands declined beyond normal variation |
Coverage leader | CrowdStrike Falcon leads with 56.3% valid recommendation coverage, down 15.1 points from August |
Second position | SentinelOne holds 48.8% valid recommendation coverage, 7.5 points behind the leader |
Third position | Sophos Intercept X holds 33.8% valid recommendation coverage |
Largest numeric decline | CrowdStrike Falcon, down 15.1 points from 71.4% in August |
Second-largest numeric decline | SentinelOne, down 12.1 points from 60.9% in August |
Widest coverage gap | CrowdStrike Falcon to Deepwatch: 55.0 points (56.3% vs. 1.3%) |
Benchmark Context
The report separates the raw collection universe from the qualified analysis set. Brand-level recommendation percentages are calculated within the qualified benchmark set.
Research stage | Jul 2026 | Sep 2026 | What it represents |
|---|---|---|---|
Source prompt-surface observations collected | 800 | 800 | Raw prompt-surface observations across the benchmark's AI/search surface universe |
Unique questions | 620 | 593 | Distinct questions posed across surfaces |
Brand / competitor mentions | 800 | 800 | Prompts mentioning a tracked brand or competitor |
Relevant prompts | 366 | 569 | Prompts relevant to the vertical |
Irrelevant prompts | 434 | 231 | Prompts not relevant to the vertical |
Qualified benchmark observations | 326 | 467 | Public denominator for brand-level metrics |
Qualified surface breadth | 6 | 6 | AI surface families with at least one qualified observation |
The qualified observation count grew from 326 to 467 across the baseline period as relevance filtering captured a larger share of the raw collection. August's 447 qualified observations sat between these two months. The metrics below summarize the aggregate benchmark independent of individual brand standings.
Benchmark-Level Metrics
Metric | Jul 2026 | Sep 2026 | Change |
|---|---|---|---|
Qualified observations | 326 | 467 | +141 |
Companies tracked | 10 | 10 | 0 |
Recommendation-shaped answer share | 31.3% | 25.9% | -5.4 points |
Valid recommendation shortlist share | 64.7% | 58.0% | -6.7 points |
Category leader by coverage | CrowdStrike Falcon | CrowdStrike Falcon | Stable position, smaller share |
The qualified observation count rose through the series while the recommendation-shaped answer share declined from 31.3% in July to 25.9% in September. August's recommendation-shaped answer share stood at 34.9%, meaning the September figure represents a sharp pullback in how often AI systems shaped answers as direct recommendations. The valid recommendation shortlist share followed a similar arc, falling from 64.7% in July to 58.0% in September after an August reading of 60.0%.
AI Recommendation Trend
The category's upper tier compressed as its leaders lost recommendation share. CrowdStrike Falcon and SentinelOne both recorded significant declines this month, narrowing the distance between the top of the field and the brands below. All tracked brands except Secureworks Taegis remained below their July coverage level; Secureworks Taegis is the only brand currently above its baseline reading.
Valid Recommendation Coverage by Brand
Brand | Jul 2026 | Sep 2026 | Movement | Sep 2026 rank |
|---|---|---|---|---|
Arctic Wolf | 25.5% | 16.9% | Down 8.6 points | 4th |
CrowdStrike Falcon | 66.0% | 56.3% | Down 9.7 points | 1st |
Deepwatch | 1.5% | 1.3% | Down 0.2 points | 10th |
eSentire | 8.0% | 3.6% | Down 4.4 points | 8th |
Expel | 8.9% | 6.6% | Down 2.3 points | 7th |
Rapid7 InsightIDR | 11.0% | 8.3% | Down 2.7 points | 5th |
Red Canary | 9.8% | 6.6% | Down 3.2 points | 6th |
Secureworks Taegis | 1.5% | 1.7% | Up 0.2 points | 9th |
SentinelOne | 56.1% | 48.8% | Down 7.3 points | 2nd |
Sophos Intercept X | 44.8% | 33.8% | Down 11.0 points | 3rd |
Five brands are classified as significant decliners this period, with four crossing the month-over-month significance threshold and eSentire's decline significant against the baseline, extending a two-month downward streak. The category-level change came from the combination of these declines across the leader tier and mid-field, rather than from any single brand's movement.
What Changed This Month
CrowdStrike Falcon
CrowdStrike Falcon remains the coverage leader but posted the largest numeric decline in the category in September, down 15.1 points from 71.4% in August to 56.3%. Against the July baseline of 66.0%, the brand is down 9.7 points, a decline classified as significant. The brand was mentioned in 94.4% of qualified observations in September, down modestly from 95.5% in August and 96.9% in July.
Placement metrics moved with the coverage decline. The top-three rate fell 8.9 points from 57.7% in July to 48.8% in September, a steep drop. The rank-one rate eased 2.4 points from 38.6% to 36.2%, a more modest change. Valid recommendation counts tell the story in absolute terms: CrowdStrike Falcon was recommended in 263 of 467 qualified observations in September, down from 319 of 447 in August, though still above the 215 of 326 in July.
The distinction to notice is that CrowdStrike Falcon's presence stayed near-universal while its recommendation rate fell. The brand remained visible in nearly every answer but was recommended less often, and when recommended, less often in a top-three slot.
Highest-priority diagnostic: which prompt categories shifted away from recommending CrowdStrike Falcon, and which competitor captured the recommendations it lost.
SentinelOne
SentinelOne declined 12.1 points from 60.9% in August to 48.8% in September, its second-place position intact but its share materially smaller. Against the July baseline of 56.1%, the brand is down 7.3 points, a significant decline. Raw mention presence moved in the opposite direction, rising 1.8 points from 83.4% in July to 85.2% in September, meaning the coverage loss came despite a small presence gain.
The top-three rate eased 2.9 points from 40.2% in July to 37.3% in September, a comparatively modest shift. The rank-one rate held flat at 2.8%. Valid recommendation counts fell from 272 of 447 qualified observations in August to 228 of 467 in September in absolute terms.
The distinction to notice is between presence and recommendation. SentinelOne's visibility in AI answers grew while its recommendation coverage fell, a divergence that points to a difference in how the brand was framed rather than a loss of recall.
Highest-priority diagnostic: whether SentinelOne appeared in more answers but in non-recommendation contexts, and which surfaces drove the presence-coverage divergence.
Sophos Intercept X
Sophos Intercept X declined 6.9 points from 40.7% in August to 33.8% in September, and 11.0 points from 44.8% in July, a significant two-month slide. The supporting metrics show a broad-based retreat: raw mention presence fell 10.8 points from 59.8% to 49.0%, the top-three rate dropped 11.3 points from 26.1% to 14.8%, and the rank-one rate fell 4.5 points from 5.8% to 1.3%. All three metrics fell together over the same period.
Valid recommendation counts dropped from 182 of 447 qualified observations in August to 158 of 467 in September. The brand remains in third place, but its distance from the leaders narrowed even as it lost ground in absolute terms, because the leaders declined more sharply.
The distinction to notice is that Sophos Intercept X's decline ran across presence, top-three placement, and rank-one outcomes simultaneously. This was not a repositioning within answers but a broad reduction in how often the brand appeared and was recommended.
Highest-priority diagnostic: which surfaces or prompt patterns account for the compounding presence and recommendation losses.
Arctic Wolf
Arctic Wolf declined 6.1 points from 23.0% in August to 16.9% in September, and 8.6 points from 25.5% in July, a significant two-month slide. Raw mention presence fell 7.7 points from 33.4% to 25.7% across the baseline period. The top-three rate eased 3.8 points from 16.9% to 13.1%, a modest change, while the rank-one rate held nearly flat at 7.1% versus 7.4%.
Valid recommendation counts fell from 103 of 447 qualified observations in August to 79 of 467 in September. The brand remains in fourth place, but its gap to third-place Sophos Intercept X narrowed to 16.9 points as both brands declined.
The distinction to notice is that Arctic Wolf's presence and coverage declined together, while its rank-one rate stayed stable. The brand retained its strongest placements even as its overall footprint shrank.
Highest-priority diagnostic: whether the presence decline reflects a shift in the qualified prompt set or a genuine reduction in how often AI systems surface Arctic Wolf.
eSentire
eSentire declined 2.2 points from 5.8% in August to 3.6% in September, and 4.4 points from 8.0% in July, a significant decline against the baseline. Raw mention presence eased 2.6 points from 10.7% to 8.1%, a modest change. The top-three rate improved slightly from 1.8% to 2.1%, while the rank-one rate held at 0.0%.
Valid recommendation counts dropped from 26 of 447 qualified observations in August to 17 of 467 in September. With only 17 valid recommendations, this small-count brand warrants careful interpretation of its movement.
The distinction to notice is that eSentire's top-three rate improved even as its overall coverage declined. The brand appears in fewer answers overall but holds a slightly stronger position when it does appear.
Highest-priority diagnostic: which answer types still recommend eSentire, and which prompts no longer include the brand.
Buyer-Intent Interpretation
Buyer-intent cluster | What it captures | Strategic question |
|---|---|---|
Brand Recommendation | Queries seeking a direct recommendation for a managed detection and response provider | Which providers do AI systems recommend, and in what order? |
Pricing & Value | Queries about cost, pricing models, and value comparisons | How does pricing information affect which providers are recommended? |
Multi-Brand Comparison | Queries comparing two or more providers head-to-head | Which providers win direct comparisons in AI-generated answers? |
All qualified observations fell into the Brand Recommendation cluster in each month of the July-to-September series. The benchmark therefore captures how AI systems recommend and rank providers in direct answer contexts, but it cannot yet answer price, value, or head-to-head comparison questions. The September qualified set did include 7 pricing analysis responses and 71 comparison analysis responses by response type, yet the buyer-intent classification placed all observations in the brand recommendation cluster. The public metrics show where brands are recommended, not how they fare on price or in direct comparison contexts.
Brand Opportunity Summary
Brand | Sep 2026 coverage | Current signal | Highest-priority diagnostic |
|---|---|---|---|
Arctic Wolf | 16.9% | Significant decline; presence and coverage down, rank-one stable | Which prompts account for the presence decline versus the stable rank-one rate? |
CrowdStrike Falcon | 56.3% | Significant decline; leader losing top-three placement | Which prompt categories shifted away from recommending the leader? |
Deepwatch | 1.3% | Stable; minimal presence in AI recommendations | Which surfaces, if any, surface Deepwatch at all? |
eSentire | 3.6% | Significant decline; coverage down from a small base | Which answer types still recommend eSentire? |
Expel | 6.6% | Stable; coverage eased, top-three rate improved | Which prompts still recommend Expel, and which no longer do? |
Rapid7 InsightIDR | 8.3% | Stable; coverage eased within variation | Which prompt patterns drove the coverage decline? |
Red Canary | 6.6% | Stable; coverage and presence eased modestly | Which surfaces reduced Red Canary's presence? |
Secureworks Taegis | 1.7% | Stable; only brand above its July coverage level | Which prompts now include Secureworks Taegis that did not before? |
SentinelOne | 48.8% | Significant decline; presence up, coverage down | Which surfaces drove the presence-coverage divergence? |
Sophos Intercept X | 33.8% | Significant decline; presence, top-three, and rank-one all down | Which surfaces or query types drove the compounding decline? |
The benchmark identifies where attention is warranted; a company-level analysis is needed to explain why.
Evidence Behind the Benchmark
The aggregate metrics are built from prompt-level observations covering the query, surface, recommendation outcome, rank, sentiment, and citations where exposed. Company-level analysis can go deeper into prompt, competitor, surface, and evidence patterns. Source presence is not automatically treated as proof of causation.
About This Benchmark
This report is part of the LLM Authority Index AI Market Discovery research program.
- AI Industry Market Discovery Methodology
- AI Industry Market Discovery Metrics
- AI Industry Market Discovery Standards
Report-Specific Interpretation Notes
- Qualified observation counts grew from 326 to 467 across the baseline period; percentages are calculated within the qualified set, so month-over-month comparison reflects both brand movement and composition changes.
- The qualified denominator differs from the raw collection universe; relevance filtering accounts for the gap.
- Five significant declines in one month point to category-level or instrument-level factors worth examining before drawing brand-specific conclusions.
- Small-count brands (Deepwatch, Secureworks Taegis, eSentire) should be interpreted with care given the low number of valid recommendations.
Next Step
The Public Benchmark Shows Where a Brand Is Winning or Losing. A Company-Level Audit Shows Why.
Beneath the aggregate coverage percentages sit the questions that matter for competitive position: which high-intent prompts a brand wins, which competitor takes the recommendation when a brand loses, what attributes AI systems associate with each option, and which external sources shape those answers. The benchmark shows that the category's leaders lost recommendation share in September, and that the declines were broad-based rather than isolated to one brand, but it does not explain why or what to do about it.
A company-specific AI visibility audit maps those prompt, surface, competitor, ranking, sentiment, and evidence-source patterns into a prioritized visibility strategy. It answers the "so what" behind each movement and identifies the specific levers that can influence AI recommendation outcomes.
/ Take the next step
Want to Understand Your AI Citation Footprint?
We start every engagement with a full audit of how AI systems reference your brand today.
Measurable, Repeatable Programme
Build a durable foundation of credible citations that compounds over time and continues to influence AI answers as new queries emerge
Citation Architecture Review
Identify which high-authority community sources are and aren't working in your favour across AI platforms.
AI Visibility Audit
Understand exactly how LLMs are referencing your brand today and which sources are shaping those answers.
/ Learn More
Understanding AI search visibility.
AI search experiences create answers by pulling information from many places online and summarizing it into a single response.


