HIGH SALIENCE / RESEARCH / ENDPOINT SECURITY TEARDOWN
TEARDOWN 11 · PUBLISHED SEPTEMBER 26, 2026 · DATASET INCLUDED
100 Questions, Eleventh Category: Endpoint Security, Where Microsoft Defender Is Picked as the Product Buyers Already Own and Picks Come as Shortlists to Test
Eleventh category, same method: 100 endpoint security queries, ChatGPT with web search on, every answer coded by two independent AI readers working from a written protocol, Google's top ten as a control. Microsoft Defender leads, and it leads as the product the buyer already pays for: it is picked in 62 answers, and in 57 of them a line naming Defender also names Microsoft 365 licensing. CrowdStrike, SentinelOne and Sophos follow. The picks come as shortlists: 93 answers pick at least one product, but only three pick exactly one, and all three pick Defender.
01Method
Same query structure, same coding, one new category.
Queries: 100 endpoint security software queries built from the same templates as the earlier teardowns: 30 category, 30 comparison, 20 alternative and 20 recommendation. The full list is in the dataset.
Surface: ChatGPT with web search forced on, logged out, United States, English, via the DataForSEO scraper, one run per query, collected September 26, 2026.
Control: Google's top ten organic results for the same queries in the same window, via the DataForSEO SERP API at depth 20 and truncated to the first ten organic results.
Coding: every answer was coded by two independent AI readers (Claude agents working blind from a written protocol), with a third settling disagreements. They were not people. Each brand named was coded picked (the answer's own verdict: "my pick", "choose X if", a shortlist it tells you to act on, the #1 of its ranking), recommended (assigned to a stated case or fit, such as "best for small teams", without being the answer's verdict), listed (named as an option, no fit given), passing (named but not offered as an option) or anchor (the brand being replaced in an "alternatives" query), against a 53-brand dictionary fixed before collection, under codebook v2.0. "Recommended" in the tables includes picked brands. The two readers agreed on 93.7% of brand codes in this teardown (97.7% at the recommended level). Cited URLs were deduplicated to their domain and classed as first-party or third-party. The third reader decided 28 of the 441 brand codes in this teardown. A rules-based first pass (the codebook v1.6 rules) agreed with the final codes on 93.7 percent at the recommended level; only the reader codes are published. The readers also coded eight brand mentions that no dictionary alias matched (named by meaning or only by a web address); those rows are in the dataset.
Collection note: the ChatGPT answers and the Google controls were collected on September 26, 2026 through the DataForSEO standard queue, between about 8:15 and 8:30 PM Mountain time (the raw files carry UTC timestamps, early September 27), with raw responses saved exactly as returned. No task failed and none was re-run. Two answers came back as a single sentence naming no products and are counted as returned. The dictionary was not changed after collection. Brands sold under two names are counted once (Malwarebytes and ThreatDown, WithSecure and F-Secure, WatchGuard and Panda Security, Kaseya and Datto); bare words such as "defender", "falcon" and "cortex" are not dictionary aliases, and any microsoft.com page counts as Microsoft Defender's own site. Two aliases that are also ordinary words (Coro, Velociraptor) match only when capitalized. AV-Comparatives and AV-TEST are not on the codebook's review-and-media list, the same list every teardown uses, so they count as other third-party pages.
One run per query, so this is a teardown, not the benchmark. Frequencies describe this window only. Absence means not observed in this sample, never zero visibility.
02Findings
A default you already own, picks written as shortlists, and test labs that do not rank.
| Brand | Appears in | Recommended in | Picked in | Picked share of appearances |
|---|---|---|---|---|
| Microsoft Defender | 68 | 67 | 62 | 91% |
| CrowdStrike | 57 | 53 | 51 | 89% |
| SentinelOne | 56 | 53 | 48 | 86% |
| Sophos | 48 | 46 | 38 | 79% |
| Bitdefender | 41 | 37 | 29 | 71% |
| Huntress | 20 | 19 | 19 | 95% |
| ESET | 19 | 16 | 13 | 68% |
| Palo Alto Cortex | 16 | 13 | 13 | 81% |
Each linked brand has its own page: how ChatGPT recommends every brand in this dataset, with positioning labels, head-to-head results and sources.
Out of 100 answers, codebook v2.0. "Picked" means the answer itself chose the brand as its verdict, overall or for a case. "Recommended" means the answer assigned the brand to a stated case or fit, and includes picked brands. "Appears" adds brands named as an option with no fit. The brand being replaced in an "alternatives" query is excluded from all columns.
The default is the one you already pay for
Microsoft Defender appears in 68 of 100 answers, is recommended in 67 and picked in 62. It is picked in 26 of the 30 general category answers and 17 of the 20 direct advice questions, and 55 of its 62 picks answer questions that do not mention it. The reason is nearly always the same. In 57 of the 62 answers that pick it, a line naming Defender also mentions Microsoft 365, Business Premium, E3 or E5 licensing, Entra, Intune or Azure; the other five sell it on price or as free with Windows. Only three answers pick a single product, and all three pick Defender: the question about the cheapest protection for a business and both nonprofit questions, which quote Business Premium's nonprofit price of $5.50 per user per month. microsoft.com is the most-cited domain, in 37 answers, 32 of them to questions that do not mention Defender.
Picks written as shortlists
Ninety-three of the 100 answers pick at least one dictionary brand, and they pick 3.4 on average. In 50 of the 93, the line that decides a pick is written as evaluation advice: "My shortlist for a serious evaluation", "I would generally evaluate Microsoft Defender for Endpoint first", "I'd run both vendors through the same proof-of-concept". Seventy-six answers ask the buyer for more detail, such as endpoint count or Microsoft licensing. The head-to-heads are decided the same way: 29 of 30 pick every brand named, each for a stated case, and none picks a brand outside the question. The exception, SentinelOne versus Cybereason, gives each a fit without choosing. Nineteen of the 20 advice questions have a pick. Of the seven answers with no pick, two came back as a single sentence naming no products; the others are a popularity list, a catalog for schools, the Cybereason comparison and two alternatives answers that describe Defender's fit without choosing it.
Three specialists behind it, and two that are described more than picked
CrowdStrike appears in 57 answers and is picked in 51, SentinelOne in 56 and 48, Sophos in 48 and 38, Bitdefender in 41 and 29. On the 20 advice questions the picks run Defender 17, CrowdStrike 15, SentinelOne 12, Sophos 10. Among brands that appear 15 or more times, Sophos and Bitdefender have the widest gap between being recommended and being picked, eight answers each: they get a fit label in the answer's table ("Smaller/mid-sized organizations", "Cost-conscious organizations wanting strong prevention") and are left off the list the answer tells the buyer to test. The healthcare advice answer shows it: Bitdefender has a row for cost-conscious buyers, and the answer's shortlist line puts Defender, CrowdStrike and SentinelOne through a formal proof of concept, then adds Sophos. Huntress, picked in 19 of the 20 answers it appears in, is the choice for MSPs, small offices, buyers with no security staff and cheaper or simpler alternatives to CrowdStrike and SentinelOne. Wazuh is picked in all four free or open source questions and Jamf Protect in both Mac questions. Kaspersky and McAfee are in the dictionary and appear in none of the 100 answers. CrowdStrike's July 2024 outage comes up in one of the 65 answers that mention CrowdStrike.
Industries, homes and firewalls
Fifteen questions outside the head-to-heads name an industry: healthcare, schools, law, nonprofits, manufacturing, accounting, retail, defense contractors, financial services and dental practices. Defender is picked in 14 of them; the fifteenth, schools, picks nothing. CrowdStrike is picked in 11, SentinelOne in 10, Sophos in 6, and Trellix's only pick in the dataset is for manufacturing plant floor PCs. Six answers read a business endpoint question as a home antivirus question and picked consumer products, and Norton's four picks all come from alternatives answers. A question about a cheaper alternative to Sophos was answered entirely as a firewall question, which is where WatchGuard's one pick comes from.
Test labs nobody ranks, and a competitor's alternatives pages
Across 100 answers there were 266 citation events to 80 domains, the fewest events in the series so far. Vendors' own sites took 149 of them, 56 percent. The most-read third parties are the two independent test labs: AV-Comparatives is cited in 11 answers across seven different test reports and AV-TEST in five, and neither ranked in Google's top ten for any of those questions. The model quotes their scores directly ("Bitdefender blocked 398/400 test cases"), and Bitdefender is picked in 9 of the 11 answers that cite a lab; it is the brand being replaced in a tenth. Gartner is also cited in 11 answers, but it ranked for nine of them. Palo Alto Networks' own "competitors and alternatives" pages were cited in four answers, including the CrowdStrike alternatives and SentinelOne alternatives questions, and Palo Alto's Cortex is picked in 13 answers, three of those four among them. Reddit and Wikipedia have zero citations, as in every teardown so far.
Of the 319 picks, 231 went to brands whose own website did not rank in Google's top ten for the question, 72 percent. SentinelOne and Huntress are the exceptions: their own sites ranked for 29 of SentinelOne's 48 picks and 16 of Huntress's 19. Defender's ranked for 9 of its 62 and CrowdStrike's for 8 of 51. Seventy-two of the 266 citation events involved a domain that also sat in Google's top ten for that query, 27 percent.
0311 categories, side by side
Same rulebook, every category so far.
| Measure (codebook v2.0) | Project management, Sept 8 | CRM, Sept 17 | Email marketing, Sept 17 | Help desk, Sept 17 | Accounting, Sept 17 | Payment processing, Sept 17 | Payroll, Sept 21 | HR software, Sept 26 | Applicant tracking, Sept 26 | Password managers, Sept 26 | Endpoint security, Sept 26 |
|---|---|---|---|---|---|---|---|---|---|---|---|
| Recommendations per category answer (average) | 5.9 | 4.3 | 5.0 | 5.5 | 4.3 | 4.2 | 4.6 | 5.0 | 4.5 | 3.4 | 4.7 |
| Answers with no recommended dictionary brand | 1 of 100 | 5 of 100 | 1 of 100 | 1 of 100 | 0 of 100 | 5 of 100 | 1 of 100 | 6 of 100 | 5 of 100 | 3 of 100 | 3 of 100 |
| Answers with no pick (the answer's own verdict) | 2 of 100 | 11 of 100 | 2 of 100 | 4 of 100 | 9 of 100 | 22 of 100 | 19 of 100 | 17 of 100 | 12 of 100 | 7 of 100 | 7 of 100 |
| Most-recommended brand: appears / recommended | Asana 73 / 73 | HubSpot 75 / 74 | Mailchimp 58 / 56 | Zendesk 70 / 69 | QuickBooks 75 / 73 | Stripe 70 / 68 | Gusto 73 / 73 | Rippling 58 / 57 | Workable 53 / 52 | Bitwarden 84 / 82 | Microsoft Defender 68 / 67 |
| Most-picked brand: appears / picked | Asana 73 / 70 | HubSpot 75 / 69 | Mailchimp 58 / 44 | Zendesk 70 / 61 | QuickBooks 75 / 65 | Stripe 70 / 54 | Gusto 73 / 61 | Rippling 58 / 50 | Workable 53 / 47 | Bitwarden 84 / 78 | Microsoft Defender 68 / 62 |
| Head-to-head queries recommending every named brand | 30 of 30 | 28 of 30 | 30 of 30 | 29 of 30 | 26 of 30 | 28 of 30 | 30 of 30 | 28 of 30 | 29 of 30 | 28 of 30 | 30 of 30 |
| Head-to-head queries picking every named brand | 30 of 30 | 23 of 30 | 29 of 30 | 29 of 30 | 25 of 30 | 19 of 30 | 21 of 30 | 21 of 30 | 29 of 30 | 27 of 30 | 29 of 30 |
| Recommendation-intent queries with a dictionary recommendation | 19 of 20 | 18 of 20 | 20 of 20 | 20 of 20 | 20 of 20 | 19 of 20 | 20 of 20 | 18 of 20 | 20 of 20 | 19 of 20 | 19 of 20 |
| Recommendation-intent queries with a pick | 19 of 20 | 18 of 20 | 20 of 20 | 20 of 20 | 19 of 20 | 18 of 20 | 20 of 20 | 18 of 20 | 20 of 20 | 19 of 20 | 19 of 20 |
| Recommended mentions where the brand does not rank in Google's top 10 | 398 of 468 (85%) | 269 of 387 (70%) | 313 of 419 (75%) | 350 of 445 (79%) | 206 of 368 (56%) | 294 of 360 (82%) | 202 of 383 (53%) | 310 of 405 (77%) | 333 of 388 (86%) | 218 of 304 (72%) | 273 of 369 (74%) |
| Picked mentions where the brand does not rank in Google's top 10 | 349 of 416 (84%) | 226 of 330 (68%) | 270 of 370 (73%) | 291 of 380 (77%) | 141 of 279 (51%) | 170 of 222 (77%) | 113 of 246 (46%) | 232 of 311 (75%) | 261 of 311 (84%) | 163 of 241 (68%) | 231 of 319 (72%) |
| Google top 10 that is third-party pages | 746 of 1,000 (75%) | 710 of 1,000 (71%) | 720 of 1,000 (72%) | 714 of 1,000 (71%) | 743 of 1,000 (74%) | 787 of 1,000 (79%) | 653 of 1,000 (65%) | 820 of 1,000 (82%) | 871 of 1,000 (87%) | 866 of 1,000 (87%) | 778 of 1,000 (78%) |
| Citation events to vendors' own sites | 216 of 362 (60%) | 136 of 320 (42%) | 193 of 367 (53%) | 152 of 345 (44%) | 125 of 302 (41%) | 161 of 301 (53%) | 192 of 314 (61%) | 167 of 325 (51%) | 139 of 311 (45%) | 201 of 292 (69%) | 149 of 266 (56%) |
| Answers citing only vendor pages | 50 of 100 | 40 of 100 | 37 of 100 | 27 of 100 | 34 of 100 | 47 of 100 | 49 of 100 | 34 of 100 | 30 of 100 | 65 of 100 | 44 of 100 |
| Share of citations in the 10 most-cited domains | 54% | 40% | 42% | 45% | 55% | 58% | 55% | 46% | 44% | 72% | 58% |
| Citation events whose domain is in Google's top 10 | 83 of 362 (23%) | 83 of 320 (26%) | 97 of 367 (26%) | 80 of 345 (23%) | 99 of 302 (33%) | 98 of 301 (33%) | 134 of 314 (43%) | 85 of 325 (26%) | 59 of 311 (19%) | 78 of 292 (27%) | 72 of 266 (27%) |
| Reddit and Wikipedia citations | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
All columns are coded under codebook v2.0 by two independent AI readers per answer; the project management column is the September 8 dataset recoded under it. Each teardown is one run per query in its own window, so differences between columns mix category with collection date.
04What this changes
Four things, in order.
If you compete with a bundle, say where the bundle stops. In 57 of Microsoft Defender's 62 picks, the answer ties it to Microsoft 365 licenses buyers already hold. A vendor selling against it needs pages that say plainly which buyers an existing Microsoft 365 license does not cover, because that is the question the model is answering.
Get on the list to test, not only in the table. Sophos and Bitdefender are each described with a fit in eight answers that then leave them off the shortlist. Pages that set out how to run a proof of concept of your product, and what it should show, fit the answer the model is already writing.
Test results are read directly. AV-Comparatives and AV-TEST were cited in 11 answers without ranking for any of them, and their protection rates were quoted as the deciding facts. Current results under your business product's name are part of your AI search footprint.
Keep business and home apart. Six answers turned business questions into home antivirus advice when the brand sells both. Vendors with consumer and business lines need pages and product names that make the business line unmistakable.
05Limitations
What this teardown cannot tell you.
One run per query means answer variance is unmeasured; Benchmark 01 runs each query three times across three surfaces. The teardowns are collected on different days, so differences between categories mix the category with the date. The brand dictionary covers the general endpoint security software market and deliberately excludes vertical tools, so their appearances are described in prose and not counted. The readers are AI models, not people: they follow a written protocol and agree with each other closely, but a shared blind spot would not show up as disagreement. The line between picked and recommended is a judgment, documented in the protocol with examples. Sentiment is not coded. No vendor-tool cross-check was read for this category. Google's control counts a brand as ranking only when its own domain is in the top ten; a listicle that features the brand does not count. One run per question, one day, United States, English, logged out. Answers vary between runs, so these are frequencies for this sample. Two answers came back as a single sentence. The line between picked and recommended was the main judgment call here: 18 of the 28 codes the third reader decided were disputes between the two, most of them over whether a shortlist or a table row was the answer's own verdict. The review-and-media list is the codebook's fixed list, so AV-Comparatives and AV-TEST count as other third-party pages here.
06Dataset
Check it, don't believe it.
Every number above can be recomputed from these files. CC BY 4.0: use them, cite the page.
- queries.csv: the 100 queries with intent labels.
- brands.csv: the 53-brand dictionary with aliases and canonical domains.
- mentions.csv: 441 coded brand mentions with position, type, a 0/1 picked column and whether the brand's domain was in Google's top ten.
- citations.csv: 266 citation events with domain class and Google overlap.
- observations.csv: one row per query with brand, recommendation, citation and control counts.
- coder-notes.md: coding notes: reader agreement, the judgment calls the readers and the third reader made, reader-added brands and dictionary notes
- codebook.md: the rulebook, with dated amendments through v2.0.
- reader-protocol.md: the written protocol both readers coded against (codebook v2.0).
- picked_stats.json: the picked-level figures.
The earlier teardowns: Teardown 01, project management, Teardown 02, crm, Teardown 03, email marketing, Teardown 04, help desk, Teardown 05, accounting, Teardown 06, payment processing, Teardown 07, payroll, Teardown 08, hr software, Teardown 09, applicant tracking, Teardown 10, password managers.
Eleven categories, and the reading list is still the story.
In endpoint security the model's picks track the vendors' own sites, a bundle buyers already own, and two independent test labs that do not rank. Finding out what the model is reading for your category is the first thing a Category Salience Brief does, with a query set you approve first.