CiteWorks Studio

How AI Search Is Recommending Managed Detection and Response: Monthly Trends

Mark HuntleyBy Mark HuntleyFounder and CEO
10 minutes read

Key Takeaways

  • CrowdStrike Falcon remained the recommendation leader at 56.3%, but its lead over SentinelOne narrowed to 7.5 points after a sharp month-over-month decline.
  • Five tracked brands posted significant declines in September 2026, with no brand recording a significant increase.
  • The category's upper tier compressed from July to September as CrowdStrike Falcon, SentinelOne, Sophos Intercept X, Arctic Wolf, and eSentire all lost recommendation coverage.
  • Qualified observations increased from 326 in July to 467 in September, even as recommendation-shaped answers and valid shortlist share both declined.

Executive Summary

CrowdStrike Falcon remains the coverage leader in AI-driven recommendations for Managed Detection and Response, but its lead narrowed sharply in September 2026. The benchmark shows CrowdStrike Falcon at 56.3% valid recommendation coverage, down 15.1 points from 71.4% in August. The gap to second-place SentinelOne narrowed to 7.5 points, with SentinelOne at 48.8% coverage after its own 12.1-point decline. Five of ten tracked brands are classified as significant decliners this period: Arctic Wolf, CrowdStrike Falcon, SentinelOne, and Sophos Intercept X each crossed the month-over-month significance threshold, while eSentire's decline is significant against the baseline with a two-month downward streak. No brand posted a significant increase.

Across the July-to-September baseline, the category's upper tier compressed notably. CrowdStrike Falcon is down 9.7 points from 66.0% in July, SentinelOne is down 7.3 points from 56.1%, and Sophos Intercept X fell 11.0 points from 44.8% to 33.8%. Arctic Wolf declined 8.6 points from 25.5% to 16.9%, and eSentire dropped 4.4 points from 8.0% to 3.6%. No tracked brand recorded a significant upward move this month.

This benchmark's July run began from 800 prompt-surface observations (620 unique questions); the September run began from 800 prompt-surface observations (593 unique questions). In both months, all 800 observations mentioned a tracked brand or competitor. Relevance filtering left 366 relevant and 434 irrelevant prompts in July, and 569 relevant and 231 irrelevant prompts in September. The public brand-level metrics are calculated from the 326 qualified observations in July and 467 qualified observations in September that survived both qualification stages.

AI recommendation trend

valid recommendation coverage, Jul 2026 to Sep 2026

0%20%40%60%80%Jul 2026Aug 2026Sep 2026
  • CrowdStrike Falcon56.3%
  • SentinelOne48.8%
  • Sophos Intercept X33.8%
  • Arctic Wolf16.9%
  • Rapid7 InsightIDR8.3%
  • Expel6.6%
  • Red Canary6.6%
  • eSentire3.6%
  • Secureworks Taegis1.7%
  • Deepwatch1.3%

Key Findings

Signal

September 2026 finding

Category status

Significant movement; five tracked brands declined beyond normal variation

Coverage leader

CrowdStrike Falcon leads with 56.3% valid recommendation coverage, down 15.1 points from August

Second position

SentinelOne holds 48.8% valid recommendation coverage, 7.5 points behind the leader

Third position

Sophos Intercept X holds 33.8% valid recommendation coverage

Largest numeric decline

CrowdStrike Falcon, down 15.1 points from 71.4% in August

Second-largest numeric decline

SentinelOne, down 12.1 points from 60.9% in August

Widest coverage gap

CrowdStrike Falcon to Deepwatch: 55.0 points (56.3% vs. 1.3%)

Benchmark Context

The report separates the raw collection universe from the qualified analysis set. Brand-level recommendation percentages are calculated within the qualified benchmark set.

Research stage

Jul 2026

Sep 2026

What it represents

Source prompt-surface observations collected

800

800

Raw prompt-surface observations across the benchmark's AI/search surface universe

Unique questions

620

593

Distinct questions posed across surfaces

Brand / competitor mentions

800

800

Prompts mentioning a tracked brand or competitor

Relevant prompts

366

569

Prompts relevant to the vertical

Irrelevant prompts

434

231

Prompts not relevant to the vertical

Qualified benchmark observations

326

467

Public denominator for brand-level metrics

Qualified surface breadth

6

6

AI surface families with at least one qualified observation

The qualified observation count grew from 326 to 467 across the baseline period as relevance filtering captured a larger share of the raw collection. August's 447 qualified observations sat between these two months. The metrics below summarize the aggregate benchmark independent of individual brand standings.

Benchmark-Level Metrics

Metric

Jul 2026

Sep 2026

Change

Qualified observations

326

467

+141

Companies tracked

10

10

0

Recommendation-shaped answer share

31.3%

25.9%

-5.4 points

Valid recommendation shortlist share

64.7%

58.0%

-6.7 points

Category leader by coverage

CrowdStrike Falcon

CrowdStrike Falcon

Stable position, smaller share

The qualified observation count rose through the series while the recommendation-shaped answer share declined from 31.3% in July to 25.9% in September. August's recommendation-shaped answer share stood at 34.9%, meaning the September figure represents a sharp pullback in how often AI systems shaped answers as direct recommendations. The valid recommendation shortlist share followed a similar arc, falling from 64.7% in July to 58.0% in September after an August reading of 60.0%.

AI Recommendation Trend

The category's upper tier compressed as its leaders lost recommendation share. CrowdStrike Falcon and SentinelOne both recorded significant declines this month, narrowing the distance between the top of the field and the brands below. All tracked brands except Secureworks Taegis remained below their July coverage level; Secureworks Taegis is the only brand currently above its baseline reading.

Valid Recommendation Coverage by Brand

Brand

Jul 2026

Sep 2026

Movement

Sep 2026 rank

Arctic Wolf

25.5%

16.9%

Down 8.6 points

4th

CrowdStrike Falcon

66.0%

56.3%

Down 9.7 points

1st

Deepwatch

1.5%

1.3%

Down 0.2 points

10th

eSentire

8.0%

3.6%

Down 4.4 points

8th

Expel

8.9%

6.6%

Down 2.3 points

7th

Rapid7 InsightIDR

11.0%

8.3%

Down 2.7 points

5th

Red Canary

9.8%

6.6%

Down 3.2 points

6th

Secureworks Taegis

1.5%

1.7%

Up 0.2 points

9th

SentinelOne

56.1%

48.8%

Down 7.3 points

2nd

Sophos Intercept X

44.8%

33.8%

Down 11.0 points

3rd

Five brands are classified as significant decliners this period, with four crossing the month-over-month significance threshold and eSentire's decline significant against the baseline, extending a two-month downward streak. The category-level change came from the combination of these declines across the leader tier and mid-field, rather than from any single brand's movement.

What Changed This Month

CrowdStrike Falcon

CrowdStrike Falcon remains the coverage leader but posted the largest numeric decline in the category in September, down 15.1 points from 71.4% in August to 56.3%. Against the July baseline of 66.0%, the brand is down 9.7 points, a decline classified as significant. The brand was mentioned in 94.4% of qualified observations in September, down modestly from 95.5% in August and 96.9% in July.

Placement metrics moved with the coverage decline. The top-three rate fell 8.9 points from 57.7% in July to 48.8% in September, a steep drop. The rank-one rate eased 2.4 points from 38.6% to 36.2%, a more modest change. Valid recommendation counts tell the story in absolute terms: CrowdStrike Falcon was recommended in 263 of 467 qualified observations in September, down from 319 of 447 in August, though still above the 215 of 326 in July.

The distinction to notice is that CrowdStrike Falcon's presence stayed near-universal while its recommendation rate fell. The brand remained visible in nearly every answer but was recommended less often, and when recommended, less often in a top-three slot.

Highest-priority diagnostic: which prompt categories shifted away from recommending CrowdStrike Falcon, and which competitor captured the recommendations it lost.

SentinelOne

SentinelOne declined 12.1 points from 60.9% in August to 48.8% in September, its second-place position intact but its share materially smaller. Against the July baseline of 56.1%, the brand is down 7.3 points, a significant decline. Raw mention presence moved in the opposite direction, rising 1.8 points from 83.4% in July to 85.2% in September, meaning the coverage loss came despite a small presence gain.

The top-three rate eased 2.9 points from 40.2% in July to 37.3% in September, a comparatively modest shift. The rank-one rate held flat at 2.8%. Valid recommendation counts fell from 272 of 447 qualified observations in August to 228 of 467 in September in absolute terms.

The distinction to notice is between presence and recommendation. SentinelOne's visibility in AI answers grew while its recommendation coverage fell, a divergence that points to a difference in how the brand was framed rather than a loss of recall.

Highest-priority diagnostic: whether SentinelOne appeared in more answers but in non-recommendation contexts, and which surfaces drove the presence-coverage divergence.

Sophos Intercept X

Sophos Intercept X declined 6.9 points from 40.7% in August to 33.8% in September, and 11.0 points from 44.8% in July, a significant two-month slide. The supporting metrics show a broad-based retreat: raw mention presence fell 10.8 points from 59.8% to 49.0%, the top-three rate dropped 11.3 points from 26.1% to 14.8%, and the rank-one rate fell 4.5 points from 5.8% to 1.3%. All three metrics fell together over the same period.

Valid recommendation counts dropped from 182 of 447 qualified observations in August to 158 of 467 in September. The brand remains in third place, but its distance from the leaders narrowed even as it lost ground in absolute terms, because the leaders declined more sharply.

The distinction to notice is that Sophos Intercept X's decline ran across presence, top-three placement, and rank-one outcomes simultaneously. This was not a repositioning within answers but a broad reduction in how often the brand appeared and was recommended.

Highest-priority diagnostic: which surfaces or prompt patterns account for the compounding presence and recommendation losses.

Arctic Wolf

Arctic Wolf declined 6.1 points from 23.0% in August to 16.9% in September, and 8.6 points from 25.5% in July, a significant two-month slide. Raw mention presence fell 7.7 points from 33.4% to 25.7% across the baseline period. The top-three rate eased 3.8 points from 16.9% to 13.1%, a modest change, while the rank-one rate held nearly flat at 7.1% versus 7.4%.

Valid recommendation counts fell from 103 of 447 qualified observations in August to 79 of 467 in September. The brand remains in fourth place, but its gap to third-place Sophos Intercept X narrowed to 16.9 points as both brands declined.

The distinction to notice is that Arctic Wolf's presence and coverage declined together, while its rank-one rate stayed stable. The brand retained its strongest placements even as its overall footprint shrank.

Highest-priority diagnostic: whether the presence decline reflects a shift in the qualified prompt set or a genuine reduction in how often AI systems surface Arctic Wolf.

eSentire

eSentire declined 2.2 points from 5.8% in August to 3.6% in September, and 4.4 points from 8.0% in July, a significant decline against the baseline. Raw mention presence eased 2.6 points from 10.7% to 8.1%, a modest change. The top-three rate improved slightly from 1.8% to 2.1%, while the rank-one rate held at 0.0%.

Valid recommendation counts dropped from 26 of 447 qualified observations in August to 17 of 467 in September. With only 17 valid recommendations, this small-count brand warrants careful interpretation of its movement.

The distinction to notice is that eSentire's top-three rate improved even as its overall coverage declined. The brand appears in fewer answers overall but holds a slightly stronger position when it does appear.

Highest-priority diagnostic: which answer types still recommend eSentire, and which prompts no longer include the brand.

Buyer-Intent Interpretation

Buyer-intent cluster

What it captures

Strategic question

Brand Recommendation

Queries seeking a direct recommendation for a managed detection and response provider

Which providers do AI systems recommend, and in what order?

Pricing & Value

Queries about cost, pricing models, and value comparisons

How does pricing information affect which providers are recommended?

Multi-Brand Comparison

Queries comparing two or more providers head-to-head

Which providers win direct comparisons in AI-generated answers?

All qualified observations fell into the Brand Recommendation cluster in each month of the July-to-September series. The benchmark therefore captures how AI systems recommend and rank providers in direct answer contexts, but it cannot yet answer price, value, or head-to-head comparison questions. The September qualified set did include 7 pricing analysis responses and 71 comparison analysis responses by response type, yet the buyer-intent classification placed all observations in the brand recommendation cluster. The public metrics show where brands are recommended, not how they fare on price or in direct comparison contexts.

Brand Opportunity Summary

Brand

Sep 2026 coverage

Current signal

Highest-priority diagnostic

Arctic Wolf

16.9%

Significant decline; presence and coverage down, rank-one stable

Which prompts account for the presence decline versus the stable rank-one rate?

CrowdStrike Falcon

56.3%

Significant decline; leader losing top-three placement

Which prompt categories shifted away from recommending the leader?

Deepwatch

1.3%

Stable; minimal presence in AI recommendations

Which surfaces, if any, surface Deepwatch at all?

eSentire

3.6%

Significant decline; coverage down from a small base

Which answer types still recommend eSentire?

Expel

6.6%

Stable; coverage eased, top-three rate improved

Which prompts still recommend Expel, and which no longer do?

Rapid7 InsightIDR

8.3%

Stable; coverage eased within variation

Which prompt patterns drove the coverage decline?

Red Canary

6.6%

Stable; coverage and presence eased modestly

Which surfaces reduced Red Canary's presence?

Secureworks Taegis

1.7%

Stable; only brand above its July coverage level

Which prompts now include Secureworks Taegis that did not before?

SentinelOne

48.8%

Significant decline; presence up, coverage down

Which surfaces drove the presence-coverage divergence?

Sophos Intercept X

33.8%

Significant decline; presence, top-three, and rank-one all down

Which surfaces or query types drove the compounding decline?

The benchmark identifies where attention is warranted; a company-level analysis is needed to explain why.

Evidence Behind the Benchmark

The aggregate metrics are built from prompt-level observations covering the query, surface, recommendation outcome, rank, sentiment, and citations where exposed. Company-level analysis can go deeper into prompt, competitor, surface, and evidence patterns. Source presence is not automatically treated as proof of causation.

About This Benchmark

This report is part of the LLM Authority Index AI Market Discovery research program.

Report-Specific Interpretation Notes

  • Qualified observation counts grew from 326 to 467 across the baseline period; percentages are calculated within the qualified set, so month-over-month comparison reflects both brand movement and composition changes.
  • The qualified denominator differs from the raw collection universe; relevance filtering accounts for the gap.
  • Five significant declines in one month point to category-level or instrument-level factors worth examining before drawing brand-specific conclusions.
  • Small-count brands (Deepwatch, Secureworks Taegis, eSentire) should be interpreted with care given the low number of valid recommendations.

Next Step

The Public Benchmark Shows Where a Brand Is Winning or Losing. A Company-Level Audit Shows Why.

Beneath the aggregate coverage percentages sit the questions that matter for competitive position: which high-intent prompts a brand wins, which competitor takes the recommendation when a brand loses, what attributes AI systems associate with each option, and which external sources shape those answers. The benchmark shows that the category's leaders lost recommendation share in September, and that the declines were broad-based rather than isolated to one brand, but it does not explain why or what to do about it.

A company-specific AI visibility audit maps those prompt, surface, competitor, ranking, sentiment, and evidence-source patterns into a prioritized visibility strategy. It answers the "so what" behind each movement and identifies the specific levers that can influence AI recommendation outcomes.

Request an AI visibility audit

/ Take the next step

Want to Understand Your AI Citation Footprint?

We start every engagement with a full audit of how AI systems reference your brand today.

Measurable, Repeatable Programme

Build a durable foundation of credible citations that compounds over time and continues to influence AI answers as new queries emerge

Citation Architecture Review

Identify which high-authority community sources are and aren't working in your favour across AI platforms.

AI Visibility Audit

Understand exactly how LLMs are referencing your brand today and which sources are shaping those answers.

/ Learn More

Understanding AI search visibility.

AI search experiences create answers by pulling information from many places online and summarizing it into a single response.

What Is AI Citation Intelligence?
AI citation intelligence is the process of measuring where AI platforms source their information and how frequently a brand is mentioned or referenced in AI-generated responses. Because LLMs synthesize across multiple sources, the sites and brands that appear repeatedly tend to influence how a topic or company is framed. This practice focuses on identifying which sources shape AI outputs and tracking brand visibility across different AI systems.
What Is Citation Architecture?
Citation architecture describes the set of sources that consistently inform how AI systems talk about a brand, product, or topic. LLMs draw from websites, articles, forums, and public discussion, and the sources they rely on most often become the backbone of their answers. Building strong citation architecture means ensuring that accurate, credible, high authority sources are the ones most likely to shape the way AI tools summarize and recommend a brand.
What Is Generative Engine Optimization?
Generative engine optimization (GEO) is the practice of improving the chances that AI systems use and cite your brand or content when generating answers. While traditional SEO is centered on ranking pages in search results, GEO focuses on how LLMs retrieve, interpret, and combine information when responding to a question. The objective is to strengthen the content and sources AI systems rely on, so your brand is treated as a trusted reference in AI responses.
What Is AI Share of Voice?
AI share of voice tracks how often a brand appears in AI-generated answers compared with competitors in the same category. It reflects visibility across AI platforms such as ChatGPT, Gemini, Claude, and Perplexity. Monitoring AI share of voice helps organizations see whether AI systems consistently include and recommend their brand for key queries or whether competitor brands are showing up more often.

About The Author

Mark Huntley

Mark Huntley

Founder and CEO

Mark Huntley, J.D. is founder of CiteWorks Studio, a strategic advisory focused on visibility, authority, and recommendation presence in AI-shaped search environments. His work centers on embedding-level GEO, vector optimization, and cosine gap engineering — helping brands align their digital presence with the retrieval systems that increasingly shape discovery, interpretation, and choice.

VIEW ALL CASE STUDIESREQUEST AN AI VISIBILITY AUDIT