Research

AI Citation Rankings Need the Questions Behind Them: CrowdStrike in MRI's October 1 Comparisons

In MRI's October 1 cybersecurity comparisons, 17 of crowdstrike.com's 24 citations answered questions naming CrowdStrike. Two measurements, read separately.

Published Machine Relations Research
Reference
TopicsMeasurementCitationsAI SearchMethodologyCybersecurity

AI citation rankings need the questions behind them. In MRI's October 1 cybersecurity comparison sample, crowdstrike.com was cited in 24 of 137 answers. Seventeen of those citations came in answers to questions that named CrowdStrike. That separates two useful measurements: being consulted when buyers evaluate a named vendor, and being selected when they have not named it.

Both are legitimate. When a buyer asks an engine to compare CrowdStrike with a rival, the vendor's own site is a reasonable source to cite, and being consulted there matters. Being chosen when the buyer has not named the vendor is a different result. A single segment rank combines the two, so reading it well means knowing how many of its questions name the brand. This page is a case study of one release of the Machine Relations Index showing how to do that.

Release and sources #

Every figure on this page is from release mri_score_v2.0+2026-10-01+b215170b2762, window 2026-05-10 to 2026-10-01. No figure from any later release is used.

The question counts, topics and named/unnamed splits come from the Index's internal run records for that release. They are not in the public API. The public API and the linked Index pages now serve a newer release, so their live numbers will differ from the ones here, and they do not expose the named/unnamed split at all.

The evidence #

Segment and domain Runs whose question names CrowdStrike Runs whose question does not
Comparisons (x_vs_y), crowdstrike.com 17 of 32 7 of 105
Comparisons (x_vs_y), huntress.com 0 of 32 9 of 105
News-driven (news_topic), crowdstrike.com 9 of 14 42 of 609
Segment Questions behind it
Each cybersecurity segment other than news (best tools, how to choose, comparisons and the rest) 7
Cybersecurity news-driven 32

A run is one question asked of one engine on one day, so many runs can come from few questions. In comparisons, 2 of the 7 questions name CrowdStrike, and they account for 32 of the 137 runs. In news, 1 of 32 questions names CrowdStrike, and it accounts for 14 of 623 runs.

Evidence file: segment-rank-question-set-2026-10-01.csv, sha256 1c4726d8cf49ea7b5ca3102f024d01f400c7da039a97069880f33fc64dab1113, 20 rows, all from release mri_score_v2.0+2026-10-01+b215170b2762. The 14 rows marked public_artifact give runs observed and runs citing the domain for crowdstrike.com and huntress.com across all seven cybersecurity question shapes, taken from the October 1 public artifact (sha256 b215170b2762f837a6aa42c04e6a63a44bd693e89c48fef844d1384d664045ed). The 6 rows marked internal_run_records hold the named/unnamed splits and question counts in the tables above, which come from the Index's internal run records.

Two measurements, read separately #

Consulted on named evaluations. On comparison questions that named CrowdStrike, crowdstrike.com was cited in 17 of 32 runs; on the one news question naming it, 9 of 14. This is what a vendor wants when a buyer is already evaluating it: the engine goes to the vendor's own material.

Selected when unnamed. On the 105 comparison runs whose question did not name CrowdStrike, the question is which sources engines chose unprompted. On those 105 runs, CrowdStrike received seven citations and Huntress nine. These counts alone do not establish a general advantage for either domain. In news, crowdstrike.com was cited in 42 of the 609 runs whose question did not name it.

The combined figure, 24 of 137, is an accurate count. It describes the mix of questions the segment happened to contain. Change how many questions name a brand and that combined figure moves, with no change in how engines treat the brand. That is a reason to report the two parts, not a reason to distrust the count.

Why the question set matters #

A segment with seven questions describes those seven questions, not a market. Survey researchers have long known that question wording and selection shape the answer, and that questionnaire design is part of the result, which is why polling standards require disclosing the exact questions asked. A citation index built on prompts inherits the same property. Language model answers can shift with prompt formatting alone, and the work that framed generative engine optimization measured visibility per query for the same reason: the query set defines what is measured.

The Index publishes a rate only above an evidence floor of 10 observed runs on 7 distinct dates, and each segment here clears it. Clearing the floor means the number was measured. It does not mean the number generalises past the questions that produced it. Changes to how the Index reports question sets are recorded in its methodology and update log, on the model of Google's Search Console data anomalies log. Index data is published under CC BY 4.0, so the release identifier travels with any figure you quote.

Running the public side yourself #

An agent can pull the published, combined figures from the Index's Model Context Protocol server at https://machinerelations.ai/mcp, using standard tools/call requests over JSON-RPC 2.0, no authentication, or from the plain HTTP API. Two copy-and-run commands:

curl -s https://machinerelations.ai/api/mri/v2/domains/crowdstrike.com | jq '.segments[] | select(.category=="cybersecurity") | {questionShape, runsCited, runsObserved, rank}'

Lists crowdstrike.com's cybersecurity segments with question shape, runs cited, runs observed and rank.

curl -s -X POST https://machinerelations.ai/mcp -H 'content-type: application/json' -H 'accept: application/json, text/event-stream' -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"mri_get_domain","arguments":{"domain":"crowdstrike.com"}}}'

Returns the same domain record through the MCP tool mri_get_domain: overall citation rate, runs cited and observed, engines citing it, a confidence tier, rank, and per-segment rows.

Both commands return the current release, not October 1, so their counts will not match this page. Check source.release.releaseId in the response to see which release you are reading. Neither call can show which questions sit behind a segment, or how a domain's citations split between questions that name it and questions that do not. That is why the evidence file above exists. To read a rank the way this page does for another release, ask the publisher for the question set and the named/unnamed split for the release you are quoting.

What this case does and does not show #

It shows that, in this release, most of crowdstrike.com's comparison citations came from questions naming CrowdStrike, and that the segment's combined count mixes two measurements worth reading separately.

It does not show why engines cited any domain, which vendor security buyers should trust, or anything about specific pages. The Index measures domains; it stores which page was cited for each event but does not publish page-level results. A different question set would produce different counts, which is the point.

FAQ #

Is it wrong for an engine to cite crowdstrike.com when the question names CrowdStrike? No. A question that names a vendor legitimately draws on that vendor's own site. Those citations measure being consulted on named evaluations, which is useful in its own right.

Does this mean CrowdStrike is cited less than the Index says? No. The published counts are accurate observations. The split shows what kind of question produced them.

Is CrowdStrike or Huntress ahead on unnamed comparison questions? On the 105 unnamed runs, CrowdStrike received seven citations and Huntress nine. These counts alone do not establish a general advantage for either domain.

Can I get the named/unnamed split from the API or MCP server? No. The splits come from the Index's internal run records for the October 1 release. The public API and MCP server serve segment totals for the current release.

The short version #

  • A segment rank describes its questions. Find out how many there are and what they ask.
  • Split a vendor's citations by whether the question names it: consulted on named evaluations, selected when unnamed.
  • Quote one release, and say which.
  • Small unnamed counts are a starting point, not a ranking.