Five products tied for the top of this category: FireMon, Microsoft Defender External Attack Surface Management, Qualys, Rapid7 and Tenable were each named in 3 of the 6 answers we collected. No single tool ran away with it, and nothing was named in more than half of the answers.
On 7 August 2026 we put six buyer questions about attack surface management software to ChatGPT and Gemini, gave each question one live web search, and wrote down every product named and every source cited. Across those 6 answers, 18 distinct product labels came up, but only six of them were named more than once, and only five reached 3 of 6.
After the five leaders, the count falls off a cliff. OWASP Amass was the only other product named in more than one answer, at 2 of 6. Every remaining product, 12 of them counting two brands the assistants spelled two different ways, was named in just 1 of 6 answers. In a category this crowded, being named twice already puts you in the top six.
The shortlist changed with every word we added
The six questions were near-synonyms, but the shortlists barely overlapped. The bare query, "best attack surface management software," returned eight products: Synack, Censys, Palo Alto Cortex Xpanse, Rapid7, Qualys, FireMon, Tenable and Microsoft Defender External Attack Surface. Three of those, Synack, Censys and Palo Alto Cortex Xpanse, showed up in that one question and nowhere else in the six.
Add the word "free" and the answer is a different universe. "Best free attack surface management software" named three tools, OWASP Amass, EasyEASM and Archery, and not one of them appears as a paid leader anywhere else. EasyEASM and Archery were named in that single question only. These are open-source projects, and the enterprise names that carry every other query, FireMon, Qualys, Tenable and Rapid7, vanish completely from the free list.
"Most affordable attack surface management software" produced a fourth distinct set of four: Microsoft Defender External Attack Surface Management, Bitsight, UpGuard and OWASP Amass. OWASP Amass is the only name that bridges "free" and "affordable." Bitsight and UpGuard each appear in this affordable question and nowhere else, so the affordable shortlist is neither the free list nor the enterprise list, it is a third thing.
The most conversational phrasing gave the strangest answer. "What attack surface management software should I use" returned just two products, SentinelOne and RiskProfiler, and both are unique to that question. Meanwhile the plainer "recommendations" and "for small teams" questions returned the stable enterprise core, FireMon, Qualys, Tenable, Rapid7 and Microsoft Defender. The small-teams question also surfaced UpGuard Breach Risk and CrowdStrike Falcon Exposure Management, each appearing only there.
The lesson for a vendor is uncomfortable. There is no single "best ASM tool" answer to win. There are at least four different competitions running, best, free, affordable and "should I use," and the product that wins one can be absent from the next three. Twelve of the 18 products we saw appeared in exactly one of the six questions.
Where the answers came from
Two domains fed every single answer: gartner.com and reddit.com, each cited in 6 of 6. A community forum and an analyst site are the two pillars this category's AI answers stand on. Quora never appeared. If your product is invisible on Reddit and absent from Gartner, you are missing the two sources that showed up in every answer.
The next tier was vendor blogs and roundups: attaxion.com, malware.news and sentinelone.com were each cited in 4 of 6 answers, and cycognito.com, paloaltonetworks.com and upguard.com in 3 of 6. These are pages that list and compare tools, so a mention on one of them is a chance to be named even when it is not your own site.
Review directories barely registered. G2 (g2.com) was cited in 3 of 6 answers, and Capterra did not appear at all. For a software category, that is worth sitting with: the star-rating directories vendors pour budget into were a minor source here, well behind Reddit, Gartner and the vendor blogs.
Here is the sharpest finding. FireMon's own domain, firemon.com, was cited in 4 of 6 answers, more than any site except Gartner and Reddit, and FireMon the product was named in 3 of 6, tied for the most-named tool in the category. The vendor that published the most-cited pages is also the most-named product. That is the whole idea in one row: the pages you publish can become the sources the AI reads back to a buyer.
It does not happen automatically, though. SentinelOne's domain was cited 4 times but SentinelOne the product was named only once, and cycognito.com was cited 3 times while CyCognito was never named at all. Being read as a source is not the same as being recommended as a product. FireMon is the case where both lined up.
What it takes to get named
If you sell in this category and want to be named, the source list is the target, not your market share. Nothing here was decided by revenue or analyst ranking. It was decided by which pages the assistant pulled on the day. The stable leaders, FireMon, Qualys, Tenable and Rapid7, are the products written about on gartner.com, reddit.com and the vendor roundups that fed these six answers.
Concretely: be present in the Reddit threads and Gartner pages cited in all 6 answers, get listed in the roundups on attaxion.com, cycognito.com and the vendor blogs cited in 3 to 4 of 6, and publish your own comparison pages, because firemon.com proves an owned domain can be one of the top three sources. If you also want the "free" or "affordable" queries, that is a separate fight with a separate shortlist, and today it is open-source names like OWASP Amass (2 of 6) and small tools like EasyEASM winning it.
The full list, counted
Below are the leaders, plus the two brands the assistants labelled two different ways, so you can see the split instead of a summed total. Microsoft Defender External Attack Surface Management (3 of 6) and the shorter "Microsoft Defender External Attack Surface" (1 of 6) are the same product counted under two names, and we leave them apart because that is what the data shows. UpGuard (1 of 6) and UpGuard Breach Risk (1 of 6) are the same story. Nine more products, not in the table, were each named once: Archery, Bitsight, Censys, CrowdStrike Falcon Exposure Management, EasyEASM, Palo Alto Cortex Xpanse, RiskProfiler, SentinelOne and Synack.
| Product | Named in | Share |
|---|---|---|
| FireMon | 3 of 6 | 50% |
| Microsoft Defender External Attack Surface Management | 3 of 6 | 50% |
| Qualys | 3 of 6 | 50% |
| Rapid7 | 3 of 6 | 50% |
| Tenable | 3 of 6 | 50% |
| OWASP Amass | 2 of 6 | 33% |
| Microsoft Defender External Attack Surface | 1 of 6 | 17% |
| UpGuard | 1 of 6 | 17% |
| UpGuard Breach Risk | 1 of 6 | 17% |
Where Glotier fits
Glotier does not sell attack surface management software, and you will not find us named in any of these 6 answers. That is correct: we are not in this category, and it would be strange for an AI to recommend us here. We ran the measurement because it is exactly the thing we do for our own customers, in their category, with their buyer questions.
If you work at one of the products above, or one that thinks it should be, the same check runs on your category in about a minute. No account, nothing to install. You paste your domain, we ask the buyer questions, and you see which products ChatGPT and Gemini name and which pages they read to decide. Whatever you find, at least you will know your number, out of six.