| Category | Function | Share | Rank | Negative rate | Labels | Quadrant | Since September 2026 |
|---|---|---|---|---|---|---|---|
| Threat intelligence platforms | Security operations | 0% | 68 of 119 | 0% | 1 | under 10 labels · led by MISP at 12% | newNew since September 2026: not ranked then, 0% now. |
| Category | September 2026 | Now | Change | Reading | Rank |
|---|---|---|---|---|---|
| Threat intel | 0% | 0% | newNew since September 2026: not ranked then, 0% now. | New this edition | Rank 68 of 119, unchanged |
Shares here are read over the models both editions asked, so they can differ by a point or two from the standing above, which counts every model in this edition.
The floor is 11 points of share, measured: how far the models move a leader on their own when the same questions are asked twice with nothing changed. A larger change is movement; a smaller one is noise, and both are shown. Movement is read over the twelve models both editions asked; GPT-6 Luna, Muse Glimmer 30B joined this edition and are in the standing but not yet in the comparison. How the floor is measured · The editions
| Model | First choice | Alternative | Mention | Negative | Labels |
|---|---|---|---|---|---|
| Claude Haiku 4.5 | 0 | 0 | 0 | 0 | 0 |
| GPT-5.4 mini | 0 | 0 | 0 | 0 | 0 |
| Gemini 3.5 Flash | 0 | 0 | 0 | 0 | 0 |
| Perplexity Sonar | 0 | 0 | 0 | 0 | 0 |
| Grok 4.1 Fast | 0 | 0 | 0 | 0 | 0 |
| Mistral Small | 0 | 0 | 0 | 0 | 0 |
| DeepSeek V4 Flash | 0 | 0 | 0 | 0 | 0 |
| Llama 4 Maverick | 0 | 0 | 0 | 0 | 0 |
| Qwen 3.7 Flash | 0 | 1 | 0 | 0 | 1 |
| Kimi K2 | 0 | 0 | 0 | 0 | 0 |
| GLM 4.7 FlashX | 0 | 0 | 0 | 0 | 0 |
| MiniMax M2.5 | 0 | 0 | 0 | 0 | 0 |
| GPT-6 Luna | 0 | 0 | 0 | 0 | 0 |
| Muse Glimmer 30B | 0 | 0 | 0 | 0 | 0 |
Verbatim evidence the judge attached to positive labels.
“Offers a free tier designed for immediate visibility across various threat domains” Qwen 3.7 Flash · Threat intel · budget prompt · alternative
Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.
Citations exist only for the models that return a source list, five of the fourteen in this edition, so these counts come from 1 of the 1 answers that named SOCRadar Labs and are not a share of its labels.
No domain is on file for SOCRadar Labs, so its own site is not marked.
Pages are listed as the models cited them.
An email the morning each edition publishes: where this product moved, where it held, and by how much against the noise floor. One address, confirmed by a click; a stop link in every email.
Already following? Everything you follow, with a stop for each.
Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when SOCRadar Labs's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as SOCRadar Labs, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.
A new claim receives the current edition's vendor brief for SOCRadar Labs by email, built from the raw record of the edition. It shows: