| Category | Function | Share | Rank | Negative rate | Labels | Quadrant | Since September 2026 |
|---|---|---|---|---|---|---|---|
| AI SOC agents | Security operations | 2% | 12 of 104 | 7% | 14 | accepted challenger | |
| AI security platforms | Security operations | 0% | 64 of 233 | 0% | 2 | under 10 labels · led by SentinelOne Singularity at 11% | |
| Enterprise AI assistants | Data platform | 0% | 112 of 145 | 0% | 1 | under 10 labels · led by ChatGPT at 25% |
| Model | First choice | Alternative | Mention | Negative | Labels |
|---|---|---|---|---|---|
| Claude Haiku 4.5 | 0 | 0 | 0 | 0 | 0 |
| GPT-5.4 mini | 0 | 1 | 1 | 0 | 2 |
| Gemini 3.5 Flash | 0 | 0 | 1 | 0 | 1 |
| Perplexity Sonar | 0 | 1 | 0 | 0 | 1 |
| Grok 4.1 Fast | 0 | 1 | 0 | 1 | 2 |
| Mistral Small | 0 | 0 | 0 | 0 | 0 |
| DeepSeek V4 Flash | 0 | 2 | 0 | 0 | 2 |
| Llama 4 Maverick | 0 | 0 | 0 | 0 | 0 |
| Qwen 3.7 Flash | 0 | 0 | 0 | 0 | 0 |
| Kimi K2 | 0 | 0 | 1 | 0 | 1 |
| GLM 4.7 FlashX | 0 | 1 | 0 | 0 | 1 |
| MiniMax M2.5 | 0 | 0 | 2 | 0 | 2 |
| GPT-6 Luna | 1 | 2 | 0 | 0 | 3 |
| Muse Glimmer 30B | 0 | 2 | 0 | 0 | 2 |
Verbatim evidence the judge attached to positive labels.
“Best low-budget pick: Microsoft Security Copilot—if your company already has Microsoft 365 E5 or E7.” GPT-6 Luna · AI SOC agents · budget prompt · first choice
“If your stack is fully Microsoft, this is the most seamless option—but it's more of a prompt-based assistant with growing autonomy” DeepSeek V4 Flash · AI SOC agents · comparative prompt · alternative
“Pick Microsoft Security Copilot or CrowdStrike Charlotte AI if your SOC already standardizes on those ecosystems.” Perplexity Sonar · AI SOC agents · comparative prompt · alternative
“Microsoft stacks (Defender/Sentinel) | Included in E5/E7 or ~$4/SCU-hour | Named agents for triage/phishing; scalable” Grok 4.1 Fast · AI SOC agents · direct prompt · alternative
Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.
“assists with queries but more copilot-like than fully agentic” Grok 4.1 Fast · AI SOC agents · comparative prompt · soft negative
Citations exist only for the models that return a source list, five of the fourteen in this edition, so these counts come from 56 of the 56 answers that named Microsoft Security Copilot and are not a share of its labels.
225 of the 225 domain citations in answers naming Microsoft Security Copilot came from somebody else's page.
Pages are listed as the models cited them.
Search figures are US estimates from DataForSEO, read October 5, 2026; AI search demand is its modeled, directional estimate, not a count of queries to any assistant. The answers are this edition's. Two measurements side by side: neither is read as the cause of the other.
An email the morning each edition publishes: where this product moved, where it held, and by how much against the noise floor. One address, confirmed by a click; a stop link in every email.
Already following? Everything you follow, with a stop for each.
What Microsoft Security Copilot's own pages state, read October 5, 2026: clarity.microsoft.com/copilot, microsoft.com/bg-bg/microsoft-copilot/locale, microsoft.com/bg-bg/microsoft-copilot/copilot-101, microsoft.com/bg-bg/microsoft-copilot/organizations, microsoft.com/bg-bg/microsoft-copilot/for-individuals. A claimed page can correct any of them.
Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when Microsoft Security Copilot's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as Microsoft Security Copilot, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.
A new claim receives the current edition's vendor brief for Microsoft Security Copilot by email, built from the raw record of the edition. It shows: