HIGH SALIENCE / RESEARCH / ENDPOINT SECURITY TEARDOWN

TEARDOWN 11 · PUBLISHED SEPTEMBER 26, 2026 · DATASET INCLUDED

100 Questions, Eleventh Category: Endpoint Security, Where Microsoft Defender Is Picked as the Product Buyers Already Own and Picks Come as Shortlists to Test

Eleventh category, same method: 100 endpoint security queries, ChatGPT with web search on, every answer coded by two independent AI readers working from a written protocol, Google's top ten as a control. Microsoft Defender leads, and it leads as the product the buyer already pays for: it is picked in 62 answers, and in 57 of them a line naming Defender also names Microsoft 365 licensing. CrowdStrike, SentinelOne and Sophos follow. The picks come as shortlists: 93 answers pick at least one product, but only three pick exactly one, and all three pick Defender.

01Method

Same query structure, same coding, one new category.

Queries: 100 endpoint security software queries built from the same templates as the earlier teardowns: 30 category, 30 comparison, 20 alternative and 20 recommendation. The full list is in the dataset.

Surface: ChatGPT with web search forced on, logged out, United States, English, via the DataForSEO scraper, one run per query, collected September 26, 2026.

Control: Google's top ten organic results for the same queries in the same window, via the DataForSEO SERP API at depth 20 and truncated to the first ten organic results.

Coding: every answer was coded by two independent AI readers (Claude agents working blind from a written protocol), with a third settling disagreements. They were not people. Each brand named was coded picked (the answer's own verdict: "my pick", "choose X if", a shortlist it tells you to act on, the #1 of its ranking), recommended (assigned to a stated case or fit, such as "best for small teams", without being the answer's verdict), listed (named as an option, no fit given), passing (named but not offered as an option) or anchor (the brand being replaced in an "alternatives" query), against a 53-brand dictionary fixed before collection, under codebook v2.0. "Recommended" in the tables includes picked brands. The two readers agreed on 93.7% of brand codes in this teardown (97.7% at the recommended level). Cited URLs were deduplicated to their domain and classed as first-party or third-party. The third reader decided 28 of the 441 brand codes in this teardown. A rules-based first pass (the codebook v1.6 rules) agreed with the final codes on 93.7 percent at the recommended level; only the reader codes are published. The readers also coded eight brand mentions that no dictionary alias matched (named by meaning or only by a web address); those rows are in the dataset.

Collection note: the ChatGPT answers and the Google controls were collected on September 26, 2026 through the DataForSEO standard queue, between about 8:15 and 8:30 PM Mountain time (the raw files carry UTC timestamps, early September 27), with raw responses saved exactly as returned. No task failed and none was re-run. Two answers came back as a single sentence naming no products and are counted as returned. The dictionary was not changed after collection. Brands sold under two names are counted once (Malwarebytes and ThreatDown, WithSecure and F-Secure, WatchGuard and Panda Security, Kaseya and Datto); bare words such as "defender", "falcon" and "cortex" are not dictionary aliases, and any microsoft.com page counts as Microsoft Defender's own site. Two aliases that are also ordinary words (Coro, Velociraptor) match only when capitalized. AV-Comparatives and AV-TEST are not on the codebook's review-and-media list, the same list every teardown uses, so they count as other third-party pages.

One run per query, so this is a teardown, not the benchmark. Frequencies describe this window only. Absence means not observed in this sample, never zero visibility.

02Findings

A default you already own, picks written as shortlists, and test labs that do not rank.

Bar chart of 8 endpoint security software brands showing, out of 100 ChatGPT answers, how many each appears in, how many recommend it and how many pick it. Microsoft Defender 68, 67 and 62, CrowdStrike 57, 53 and 51, SentinelOne 56, 53 and 48, Sophos 48, 46 and 38, Bitdefender 41, 37 and 29, Huntress 20, 19 and 19, ESET 19, 16 and 13, Palo Alto Cortex 16, 13 and 13.
BrandAppears inRecommended inPicked inPicked share of appearances
Microsoft Defender68676291%
CrowdStrike57535189%
SentinelOne56534886%
Sophos48463879%
Bitdefender41372971%
Huntress20191995%
ESET19161368%
Palo Alto Cortex16131381%

Each linked brand has its own page: how ChatGPT recommends every brand in this dataset, with positioning labels, head-to-head results and sources.

Out of 100 answers, codebook v2.0. "Picked" means the answer itself chose the brand as its verdict, overall or for a case. "Recommended" means the answer assigned the brand to a stated case or fit, and includes picked brands. "Appears" adds brands named as an option with no fit. The brand being replaced in an "alternatives" query is excluded from all columns.

The default is the one you already pay for

Microsoft Defender appears in 68 of 100 answers, is recommended in 67 and picked in 62. It is picked in 26 of the 30 general category answers and 17 of the 20 direct advice questions, and 55 of its 62 picks answer questions that do not mention it. The reason is nearly always the same. In 57 of the 62 answers that pick it, a line naming Defender also mentions Microsoft 365, Business Premium, E3 or E5 licensing, Entra, Intune or Azure; the other five sell it on price or as free with Windows. Only three answers pick a single product, and all three pick Defender: the question about the cheapest protection for a business and both nonprofit questions, which quote Business Premium's nonprofit price of $5.50 per user per month. microsoft.com is the most-cited domain, in 37 answers, 32 of them to questions that do not mention Defender.

Picks written as shortlists

Ninety-three of the 100 answers pick at least one dictionary brand, and they pick 3.4 on average. In 50 of the 93, the line that decides a pick is written as evaluation advice: "My shortlist for a serious evaluation", "I would generally evaluate Microsoft Defender for Endpoint first", "I'd run both vendors through the same proof-of-concept". Seventy-six answers ask the buyer for more detail, such as endpoint count or Microsoft licensing. The head-to-heads are decided the same way: 29 of 30 pick every brand named, each for a stated case, and none picks a brand outside the question. The exception, SentinelOne versus Cybereason, gives each a fit without choosing. Nineteen of the 20 advice questions have a pick. Of the seven answers with no pick, two came back as a single sentence naming no products; the others are a popularity list, a catalog for schools, the Cybereason comparison and two alternatives answers that describe Defender's fit without choosing it.

Three specialists behind it, and two that are described more than picked

CrowdStrike appears in 57 answers and is picked in 51, SentinelOne in 56 and 48, Sophos in 48 and 38, Bitdefender in 41 and 29. On the 20 advice questions the picks run Defender 17, CrowdStrike 15, SentinelOne 12, Sophos 10. Among brands that appear 15 or more times, Sophos and Bitdefender have the widest gap between being recommended and being picked, eight answers each: they get a fit label in the answer's table ("Smaller/mid-sized organizations", "Cost-conscious organizations wanting strong prevention") and are left off the list the answer tells the buyer to test. The healthcare advice answer shows it: Bitdefender has a row for cost-conscious buyers, and the answer's shortlist line puts Defender, CrowdStrike and SentinelOne through a formal proof of concept, then adds Sophos. Huntress, picked in 19 of the 20 answers it appears in, is the choice for MSPs, small offices, buyers with no security staff and cheaper or simpler alternatives to CrowdStrike and SentinelOne. Wazuh is picked in all four free or open source questions and Jamf Protect in both Mac questions. Kaspersky and McAfee are in the dictionary and appear in none of the 100 answers. CrowdStrike's July 2024 outage comes up in one of the 65 answers that mention CrowdStrike.

Industries, homes and firewalls

Fifteen questions outside the head-to-heads name an industry: healthcare, schools, law, nonprofits, manufacturing, accounting, retail, defense contractors, financial services and dental practices. Defender is picked in 14 of them; the fifteenth, schools, picks nothing. CrowdStrike is picked in 11, SentinelOne in 10, Sophos in 6, and Trellix's only pick in the dataset is for manufacturing plant floor PCs. Six answers read a business endpoint question as a home antivirus question and picked consumer products, and Norton's four picks all come from alternatives answers. A question about a cheaper alternative to Sophos was answered entirely as a firewall question, which is where WatchGuard's one pick comes from.

Test labs nobody ranks, and a competitor's alternatives pages

Across 100 answers there were 266 citation events to 80 domains, the fewest events in the series so far. Vendors' own sites took 149 of them, 56 percent. The most-read third parties are the two independent test labs: AV-Comparatives is cited in 11 answers across seven different test reports and AV-TEST in five, and neither ranked in Google's top ten for any of those questions. The model quotes their scores directly ("Bitdefender blocked 398/400 test cases"), and Bitdefender is picked in 9 of the 11 answers that cite a lab; it is the brand being replaced in a tenth. Gartner is also cited in 11 answers, but it ranked for nine of them. Palo Alto Networks' own "competitors and alternatives" pages were cited in four answers, including the CrowdStrike alternatives and SentinelOne alternatives questions, and Palo Alto's Cortex is picked in 13 answers, three of those four among them. Reddit and Wikipedia have zero citations, as in every teardown so far.

Of the 319 picks, 231 went to brands whose own website did not rank in Google's top ten for the question, 72 percent. SentinelOne and Huntress are the exceptions: their own sites ranked for 29 of SentinelOne's 48 picks and 16 of Huntress's 19. Defender's ranked for 9 of its 62 and CrowdStrike's for 8 of 51. Seventy-two of the 266 citation events involved a domain that also sat in Google's top ten for that query, 27 percent.

0311 categories, side by side

Same rulebook, every category so far.

Measure (codebook v2.0)Project management, Sept 8CRM, Sept 17Email marketing, Sept 17Help desk, Sept 17Accounting, Sept 17Payment processing, Sept 17Payroll, Sept 21HR software, Sept 26Applicant tracking, Sept 26Password managers, Sept 26Endpoint security, Sept 26
Recommendations per category answer (average)5.94.35.05.54.34.24.65.04.53.44.7
Answers with no recommended dictionary brand1 of 1005 of 1001 of 1001 of 1000 of 1005 of 1001 of 1006 of 1005 of 1003 of 1003 of 100
Answers with no pick (the answer's own verdict)2 of 10011 of 1002 of 1004 of 1009 of 10022 of 10019 of 10017 of 10012 of 1007 of 1007 of 100
Most-recommended brand: appears / recommendedAsana 73 / 73HubSpot 75 / 74Mailchimp 58 / 56Zendesk 70 / 69QuickBooks 75 / 73Stripe 70 / 68Gusto 73 / 73Rippling 58 / 57Workable 53 / 52Bitwarden 84 / 82Microsoft Defender 68 / 67
Most-picked brand: appears / pickedAsana 73 / 70HubSpot 75 / 69Mailchimp 58 / 44Zendesk 70 / 61QuickBooks 75 / 65Stripe 70 / 54Gusto 73 / 61Rippling 58 / 50Workable 53 / 47Bitwarden 84 / 78Microsoft Defender 68 / 62
Head-to-head queries recommending every named brand30 of 3028 of 3030 of 3029 of 3026 of 3028 of 3030 of 3028 of 3029 of 3028 of 3030 of 30
Head-to-head queries picking every named brand30 of 3023 of 3029 of 3029 of 3025 of 3019 of 3021 of 3021 of 3029 of 3027 of 3029 of 30
Recommendation-intent queries with a dictionary recommendation19 of 2018 of 2020 of 2020 of 2020 of 2019 of 2020 of 2018 of 2020 of 2019 of 2019 of 20
Recommendation-intent queries with a pick19 of 2018 of 2020 of 2020 of 2019 of 2018 of 2020 of 2018 of 2020 of 2019 of 2019 of 20
Recommended mentions where the brand does not rank in Google's top 10398 of 468 (85%)269 of 387 (70%)313 of 419 (75%)350 of 445 (79%)206 of 368 (56%)294 of 360 (82%)202 of 383 (53%)310 of 405 (77%)333 of 388 (86%)218 of 304 (72%)273 of 369 (74%)
Picked mentions where the brand does not rank in Google's top 10349 of 416 (84%)226 of 330 (68%)270 of 370 (73%)291 of 380 (77%)141 of 279 (51%)170 of 222 (77%)113 of 246 (46%)232 of 311 (75%)261 of 311 (84%)163 of 241 (68%)231 of 319 (72%)
Google top 10 that is third-party pages746 of 1,000 (75%)710 of 1,000 (71%)720 of 1,000 (72%)714 of 1,000 (71%)743 of 1,000 (74%)787 of 1,000 (79%)653 of 1,000 (65%)820 of 1,000 (82%)871 of 1,000 (87%)866 of 1,000 (87%)778 of 1,000 (78%)
Citation events to vendors' own sites216 of 362 (60%)136 of 320 (42%)193 of 367 (53%)152 of 345 (44%)125 of 302 (41%)161 of 301 (53%)192 of 314 (61%)167 of 325 (51%)139 of 311 (45%)201 of 292 (69%)149 of 266 (56%)
Answers citing only vendor pages50 of 10040 of 10037 of 10027 of 10034 of 10047 of 10049 of 10034 of 10030 of 10065 of 10044 of 100
Share of citations in the 10 most-cited domains54%40%42%45%55%58%55%46%44%72%58%
Citation events whose domain is in Google's top 1083 of 362 (23%)83 of 320 (26%)97 of 367 (26%)80 of 345 (23%)99 of 302 (33%)98 of 301 (33%)134 of 314 (43%)85 of 325 (26%)59 of 311 (19%)78 of 292 (27%)72 of 266 (27%)
Reddit and Wikipedia citations00000000000

All columns are coded under codebook v2.0 by two independent AI readers per answer; the project management column is the September 8 dataset recoded under it. Each teardown is one run per query in its own window, so differences between columns mix category with collection date.

04What this changes

Four things, in order.

If you compete with a bundle, say where the bundle stops. In 57 of Microsoft Defender's 62 picks, the answer ties it to Microsoft 365 licenses buyers already hold. A vendor selling against it needs pages that say plainly which buyers an existing Microsoft 365 license does not cover, because that is the question the model is answering.

Get on the list to test, not only in the table. Sophos and Bitdefender are each described with a fit in eight answers that then leave them off the shortlist. Pages that set out how to run a proof of concept of your product, and what it should show, fit the answer the model is already writing.

Test results are read directly. AV-Comparatives and AV-TEST were cited in 11 answers without ranking for any of them, and their protection rates were quoted as the deciding facts. Current results under your business product's name are part of your AI search footprint.

Keep business and home apart. Six answers turned business questions into home antivirus advice when the brand sells both. Vendors with consumer and business lines need pages and product names that make the business line unmistakable.

05Limitations

What this teardown cannot tell you.

One run per query means answer variance is unmeasured; Benchmark 01 runs each query three times across three surfaces. The teardowns are collected on different days, so differences between categories mix the category with the date. The brand dictionary covers the general endpoint security software market and deliberately excludes vertical tools, so their appearances are described in prose and not counted. The readers are AI models, not people: they follow a written protocol and agree with each other closely, but a shared blind spot would not show up as disagreement. The line between picked and recommended is a judgment, documented in the protocol with examples. Sentiment is not coded. No vendor-tool cross-check was read for this category. Google's control counts a brand as ranking only when its own domain is in the top ten; a listicle that features the brand does not count. One run per question, one day, United States, English, logged out. Answers vary between runs, so these are frequencies for this sample. Two answers came back as a single sentence. The line between picked and recommended was the main judgment call here: 18 of the 28 codes the third reader decided were disputes between the two, most of them over whether a shortlist or a table row was the answer's own verdict. The review-and-media list is the codebook's fixed list, so AV-Comparatives and AV-TEST count as other third-party pages here.

06Dataset

Check it, don't believe it.

Every number above can be recomputed from these files. CC BY 4.0: use them, cite the page.

  • queries.csv: the 100 queries with intent labels.
  • brands.csv: the 53-brand dictionary with aliases and canonical domains.
  • mentions.csv: 441 coded brand mentions with position, type, a 0/1 picked column and whether the brand's domain was in Google's top ten.
  • citations.csv: 266 citation events with domain class and Google overlap.
  • observations.csv: one row per query with brand, recommendation, citation and control counts.
  • coder-notes.md: coding notes: reader agreement, the judgment calls the readers and the third reader made, reader-added brands and dictionary notes
  • codebook.md: the rulebook, with dated amendments through v2.0.
  • reader-protocol.md: the written protocol both readers coded against (codebook v2.0).
  • picked_stats.json: the picked-level figures.

The earlier teardowns: Teardown 01, project management, Teardown 02, crm, Teardown 03, email marketing, Teardown 04, help desk, Teardown 05, accounting, Teardown 06, payment processing, Teardown 07, payroll, Teardown 08, hr software, Teardown 09, applicant tracking, Teardown 10, password managers.

Eleven categories, and the reading list is still the story.

In endpoint security the model's picks track the vendors' own sites, a bundle buyers already own, and two independent test labs that do not rank. Finding out what the model is reading for your category is the first thing a Category Salience Brief does, with a query set you approve first.