CrowdStrike's Fal.Con 2026 event in Las Vegas saw new integrations between its security workflows and data protectors Commvault and Rubrik, plus AI data storage and processing supplier VAST Data
Commvault and Rubrik have API-level connectors between CrowdStrike’s AI security agent, Charlotte Agentic SOAR, and their own data protecting activities, which are kicked off by them detecting cyber-security threats. Now Charlotte Agentic SOAR can trigger them as well.
The VAST Data integration is different as CrowdStrike’s Charlott Agentic SOAR is not involved, VAST connecting at a lower, non-agent level, as it were, with CrowdStrike’s Falcon-class facilities.
Commvault
CrowdStrike’s Charlotte Agentic SOAR workflows can initiate Commvault cyber-recovery actions when attacks are detected to lock down backup systems and prevent recovery points from being deleted or overwritten. They can also restore potentially compromised assets into Commvault’s Cleanroom for forensic investigation.
The SOAR acronym stands for Security Orchestration, Automation and Response. Charlotte Agentic SOAR is CrowdStrike’s orchestration layer for an agentic SOC (Security Operations Center). It combines traditional SOAR automation (via CrowdStrike’s Falcon Fusion SOAR) with AI agents, powered by Charlotte AI, so security teams can coordinate reasoning agents, automated actions, and human oversight in one system. Charlotte Agentic SOAR adds LLM-based agents to traditional static SOAR playbooks and fixed if-then workflows. The agents interpret context, adapt in real time, and decide next steps, while using structured workflow logic for consistency and control.
Vidya Shankaran, Field CTO, Commvault, said: “Our integration with CrowdStrike Charlotte Agentic SOAR makes Commvault cyber recovery actions available directly within security workflows, helping joint customers reduce manual handoffs and accelerate investigation and response. This strengthens cyber resilience and simplifies how security and recovery teams work together seamlessly.”
Commvault says the integration, a purpose-built connector, enables joint customers to automate Commvault recovery actions as part of CrowdStrike security workflows. This can restrict access in Commvault to help prevent unauthorised changes during an active incident, and preserve clean recovery options by automatically suspending Commvault backup data ageing policies to retain viable recovery points during active incidents.
It can help accelerate response and forensic investigations by restoring potentially compromised data assets into Commvault’s Cleanroom, enabling investigators to begin analysis without disrupting production systems. Finally, the integration can reduce time-consuming manual coordination between security and recovery teams.
Earlier this year Commvault integrated its AI-powered anomaly alerts and other security capabilities into CrowdStrike software to enable faster, more precise responses to cybersecurity events. And Commvault integrated CrowdStrike's malware-detecting Falcon XDR into its Commvault Cloud in January last year.
Commvault is a platinum sponsor of Fal.Con 2026, lower than, in order, Pinnacle, Premier, and Diamond sponsors, but higher than Gold, Silver, Innovator and LATAM ones.
Rubrik
CrowdStrike and Rubrik say they are providing closed-loop agentic identity resilience workflows to recover from identity-based attacks at machine speed. The two will provide security teams with a complete, agentic identity resilience workflow orchestrated by Charlotte Agentic SOAR.
This combines real-time threat detection and response from Falcon Next-Gen Identity Security with automated data and identity protection with Rubrik Identity Resilience. The two say organizations can now detect, investigate, and recover from compromised identity environments in hours rather than days.
Daniel Bernard, Chief Business Officer at CrowdStrike, said: "By bringing CrowdStrike and Rubrik together via agentic workflows, we're empowering organizations to contain and recover from identity-based attacks faster than ever.”
Anneka Gupta, Rubrik’s Chief Product Officer, said: “We integrated Rubrik and CrowdStrike because you can't fight rapid AI threats with manual workflows. You need automated, intelligent defense to shut down active attacks instantly and guarantee a clean, fast recovery.”
An example of what the integration can bring is that CrowdStrike detects and contains malicious activity, while Rubrik correlates detection data with identity activity logs. Context within Human Resources Information Systems (HRIS) and IGA solutions can be scanned for threats across backup data. Teams can then surgically undo malicious Active Directory changes or trigger automated (AD) forest recovery plans while removing malicious files. From detection to recovery, The incident is detected, a response initiated, and then closed with minimal manual intervention.
Rubrik says this announcement builds on the existing identity-forward integrations that Rubrik supports from CrowdStrike, including Falcon Next-Gen SIEM, Charlotte Agentic SOAR, Falcon Next-Gen Identity Security, and Threat Intelligence.
The company is a Premier sponsor of Fal.Con 2026.
VAST Data
Bernard said: “AI is reshaping the enterprise, and security has to extend everywhere AI operates. By bringing CrowdStrike into the VAST AI Operating System, we’re extending Falcon protection across the infrastructure, data and AI pipelines powering the next generation of enterprise AI. VAST Data is one of the most innovative AI infrastructure software companies on the market – secured by CrowdStrike.”
VAST Data’s AI Operating System natively supports CrowdStrike’s Falcon sensor, bringing CrowdStrike protection directly into the VAST environment. VAST audit telemetry will integrate directly with CrowdStrike Falcon Next-Gen SIEM, combining detailed visibility into how users and machines access enterprise data with CrowdStrike’s threat intelligence and detection capabilities. Security teams will be able to correlate activity across the VAST AI OS with the broader cyber environment to identify anomalous behavior, investigate incidents and better understand the scope of potential threats.
This establishes a foundation for deeper integrations with Falcon Guardian, CrowdStrike’s new AI Detection and Response (AIDR) offering. Falcon Guardian will integrate with VAST InsightEngine, leveraging the Nvidia AI Data Platform reference design, to bring threat detection into the pipelines preparing enterprise data for AI. As InsightEngine ingests, processes and enriches data for AI knowledge bases and workflows, organisations will be able to use Guardian to identify sensitive or risky information, and surface potentially harmful activity before it reaches downstream AI systems.
CrowdStrike can detect threats such as prompt injection, jailbreak attempts and other malicious activity, helping organisations identify risk across both the data feeding AI and the activity around it.
Renen Hallak, Founder & CEO at VAST Data, said: “The security boundary for AI can’t stop at the infrastructure. Enterprises need to understand who is accessing their data, how that data is moving through AI pipelines and what is happening when applications and models interact with it. Together with CrowdStrike, we’re bringing security across each of those layers. By combining the VAST AI Operating System with the intelligence of the Falcon platform, customers can build AI environments where security is part of the architecture from the foundation through the AI pipeline.”
VAST Data is a Gold-level sponsor of Fal.Con 2026.
Comment
We wonder that a Charlotte Agentic SOAR integration has not been announced between CrowdStrike and Cohesity, a Silver-level Fal.Con 2026 sponsor.
There are existing integrations between Cohesity DataHawk and CrowdStrike’s Falcon LogScale to pushes security signals from secondary data into Falcon. Also CrowdStrike Falcon Adversary Intelligence feeds are imported into Cohesity’s Data Cloud threat library.
It is surprising that Cohesity and CrowdStrike are not replicating the latest Commvault and Rubrik CrowdStrike agent level integrations.
Veeam is also behind the curve here. It and CrowdStrike partnered in April last year to put Veeam Data Platform events into Falcon LogScale and Falcon Next-Gen SIEM. This is a 1-way deal in contrast to the 2-way Cohesity-Commvault deal.
We are surely going to see CrowdStrike agentic AI-level integrations for Cohesity and Veeam in the relatively near future.
Availability
The integration between Commvault and Charlotte Agentic SOAR is generally available for joint Commvault and CrowdStrike customers. The integration is also available through the CrowdStrike Marketplace.
There is no availability date for the Rubrik-CrowdStrike Charlotte Agentic SOAR integration.
Native CrowdStrike Falcon sensor support for VAST Data is certified and available today. VAST integrations with CrowdStrike Falcon Next-Gen SIEM and Falcon Guardian are available in private preview. Learn more here.