SecRespond - Persistence Mechanism Detection: leaderboard
Metric: Detection CAP-score (%) on the Persistence Mechanism (PER) capability dimension: the detection (discovery, evidence and root-cause attribution, 0-3 per checkpoint) score achieved over all checkpoints mapped to the dimension across the 10 SecRespond cyber ranges (averaged over three LLM judges); agents in the OpenCode harness with reasoning enabled; higher is better. Source: arxiv.org. Saturation forecast: Around December 2026. 23 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | Qwen 3.7 Max (Thinking) | 79 |
| 2 | GPT-5.4 Pro (xHigh) | 76.4 |
| 3 | Claude Opus 4.6 (Thinking) | 72.1 |
| 4 | GPT-5.5 | 71.3 |
| 5 | GLM-5.1 | 68.4 |
| 6 | GPT-5.2 Pro | 67.6 |
| 7 | Claude Sonnet 4.6 (Thinking) | 58.7 |
| 8 | Kimi K2.6 (Thinking) | 57.9 |
| 9 | Qwen 3.6 Plus (Thinking) | 57.5 |
| 10 | Claude Opus 4.5 (Thinking) | 56.9 |
| 11 | Claude Sonnet 4.5 (Thinking) | 56.1 |
| 12 | GLM-5 | 54.2 |
| 13 | Kimi K2.5 (Thinking) | 49.5 |
| 14 | Qwen 3.5 Plus (Thinking) | 49.5 |
| 15 | Gemini 3.1 Pro (Preview) | 48.7 |
Interactive version: theaggregate.ai/benchmark?slug=secrespond-persistence-mechanism-detection · How It Works · Data refreshed daily, snapshot 2026-09-29.