| Category | Function | Share | Rank | Negative rate | Labels | Quadrant |
|---|---|---|---|---|---|---|
| Endpoint detection and response | Security operations | 6% | 7 of 54 | 31% | 13 | criticized challenger |
| Endpoint protection | IT operations and endpoint | 4% | 8 of 99 | 17% | 18 | accepted challenger |
| Managed detection and response | Security operations | 2% | 8 of 45 | 0% | 6 | under 10 labels · led by Arctic Wolf Managed Detection and Response at 39% |
| Cloud security posture management | Cloud and infrastructure | 2% | 9 of 53 | 0% | 7 | under 10 labels · led by Wiz at 43% |
| Vulnerability management platforms | Security operations | 0% | 25 of 80 | 17% | 6 | under 10 labels · led by Rapid7 InsightVM at 45% |
| Cloud-native application protection | Cloud and infrastructure | 0% | 21 of 57 | 0% | 4 | under 10 labels · led by Wiz at 46% |
| Container and Kubernetes security | Cloud and infrastructure | 0% | 22 of 78 | 0% | 4 | under 10 labels · led by Aqua Security at 18% |
| Attack surface management | Security operations | 0% | 34 of 104 | 0% | 2 | under 10 labels · led by Intruder at 59% |
| Penetration testing as a service | Security operations | 0% | 70 of 76 | 50% | 2 | under 10 labels · led by Cobalt at 44% |
| SIEM platforms | Security operations | 0% | 22 of 49 | 0% | 2 | under 10 labels · led by Microsoft Sentinel at 41% |
| Threat intelligence platforms | Security operations | 0% | 103 of 128 | 50% | 2 | under 10 labels · led by NordStellar at 13% |
| Data loss prevention | Security operations | 0% | 27 of 84 | 0% | 1 | under 10 labels · led by Microsoft Purview DLP at 39% |
| SOAR platforms | Security operations | 0% | 37 of 49 | 0% | 1 | under 10 labels · led by Tines at 47% |
| Model | First choice | Alternative | Mention | Negative | Labels |
|---|---|---|---|---|---|
| Claude Haiku 4.5 | 0 | 1 | 6 | 1 | 8 |
| GPT-5.4 mini | 0 | 2 | 1 | 1 | 4 |
| Gemini 3.5 Flash | 1 | 2 | 2 | 2 | 7 |
| Perplexity Sonar | 0 | 0 | 1 | 1 | 2 |
| Grok 4.1 Fast | 1 | 4 | 4 | 2 | 11 |
| Mistral Small | 1 | 2 | 2 | 0 | 5 |
| DeepSeek V4 Flash | 1 | 1 | 2 | 0 | 4 |
| Llama 4 Maverick | 1 | 0 | 3 | 0 | 4 |
| Qwen 3.7 Flash | 0 | 4 | 5 | 3 | 12 |
| Kimi K2 | 2 | 0 | 4 | 0 | 6 |
| GLM 4.7 FlashX | 0 | 0 | 2 | 0 | 2 |
| MiniMax M2.5 | 0 | 1 | 2 | 0 | 3 |
Verbatim evidence the judge attached to positive labels.
“The best EDR platform for a mid-market B2B company is CrowdStrike, as it combines protection, scalability, and manageable cloud delivery better than the rest of the field.” Llama 4 Maverick · EDR · direct prompt · first choice
“CrowdStrike Falcon: Widely considered the gold standard for efficacy and lightweight agent, but can be highly priced. Their MDR service (Falcon Complete) is top-tier.” Gemini 3.5 Flash · EDR · scale prompt · first choice
“The leading contenders to shortlist would be CrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint” DeepSeek V4 Flash · Endpoint protection · scale prompt · first choice
“CrowdStrike Falcon | Market leader, strong threat intel | Organizations wanting best-in-class detection” Kimi K2 · Endpoint protection · scale prompt · first choice
Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.
“The July 2024 CrowdStrike content update incident, which caused widespread Windows failures globally, changed how mature buyers evaluate every EDR vendor.” Claude Haiku 4.5 · EDR · negative prompt · soft negative
“While top-tier, their commercial feeds can be incredibly aggressive... Use their *Intel*, not necessarily their automatic *Blocking*.” Qwen 3.7 Flash · Threat intel · negative prompt · soft negative
“The July 2024 global CrowdStrike outage—triggered by a faulty rapid-response sensor update—highlighted a major risk” Gemini 3.5 Flash · EDR · negative prompt · soft negative
“Most Expensive: Custom Manual Pen Test (Enterprise firms like Mandiant or CrowdStrike, usually $50k+)” Qwen 3.7 Flash · PTaaS · direct prompt · soft negative
Citations exist only for the models that return a source list, four of the twelve in this edition, so these counts come from 153 of the 199 answers that named CrowdStrike and are not a share of its labels.
406 of the 406 domain citations in answers naming CrowdStrike came from somebody else's page.
Pages are listed as the models cited them.
Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when CrowdStrike's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as CrowdStrike, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.
It does not get any change to labels, shares or verdicts, any preview, or any say over which quotes appear. A verification link goes to your work email; an address at crowdstrike.com is approved on the spot, any other address is reviewed by hand.
Your name and company appear on the claimed page, or the company alone if you ask below. A title and a LinkedIn address appear there too if you give them, and are left off if you do not. Your email address is never published.