CrowdStrike’s security agents can trigger Commvault, Rubrik and VAST Data cyber-recovery CrowdStrike announced at its Fal.Con 2026 event in Las Vegas that its Charlotte Agentic SOAR security agent can now trigger cyber-recovery actions in Commvault and Rubrik, with a separate integration for VAST Data. The integrations aim to automate incident response and forensic investigations, reducing manual coordination between security and recovery teams. CrowdStrike’s security agents can trigger Commvault, Rubrik and VAST Data cyber-recovery CrowdStrike's Fal.Con 2026 https://www.crowdstrike.com/en-us/events/fal-con/las-vegas/at-a-glance/ event in Las Vegas saw new integrations between its security workflows and data protectors Commvault and Rubrik, plus AI data storage and processing supplier VAST Data Commvault and Rubrik have API-level connectors between CrowdStrike’s AI security agent, Charlotte Agentic SOAR, and their own data protecting activities, which are kicked off by them detecting cyber-security threats. Now Charlotte Agentic SOAR can trigger them as well. The VAST Data integration is different as CrowdStrike’s Charlott Agentic SOAR is not involved, VAST connecting at a lower, non-agent level, as it were, with CrowdStrike’s Falcon-class facilities. Commvault CrowdStrike’s Charlotte Agentic SOAR workflows can initiate Commvault https://www.blocksandfiles.com/public-cloud/2026/08/18/commvault-cloud-rewind-now-wraps-round-even-more-azure/5289165 cyber-recovery actions when attacks are detected to lock down backup systems and prevent recovery points from being deleted or overwritten. They can also restore potentially compromised assets into Commvault’s Cleanroom for forensic investigation. The SOAR acronym stands for Security Orchestration, Automation and Response. Charlotte Agentic SOAR https://www.crowdstrike.com/en-us/platform/charlotte-ai/agentic-soar/ is CrowdStrike’s orchestration layer for an agentic SOC Security Operations Center . It combines traditional SOAR automation via CrowdStrike’s Falcon Fusion SOAR with AI agents, powered by Charlotte AI, so security teams can coordinate reasoning agents, automated actions, and human oversight in one system. Charlotte Agentic SOAR adds LLM-based agents to traditional static SOAR playbooks and fixed if-then workflows. The agents interpret context, adapt in real time, and decide next steps, while using structured workflow logic for consistency and control. Vidya Shankaran, Field CTO, Commvault, said: “Our integration with CrowdStrike Charlotte Agentic SOAR makes Commvault cyber recovery actions available directly within security workflows, helping joint customers reduce manual handoffs and accelerate investigation and response. This strengthens cyber resilience and simplifies how security and recovery teams work together seamlessly.” Commvault says the integration, a purpose-built connector, enables joint customers to automate Commvault recovery actions as part of CrowdStrike security workflows. This can restrict access in Commvault to help prevent unauthorised changes during an active incident, and preserve clean recovery options by automatically suspending Commvault backup data ageing policies to retain viable recovery points during active incidents. It can help accelerate response and forensic investigations by restoring potentially compromised data assets into Commvault’s Cleanroom, enabling investigators to begin analysis without disrupting production systems. Finally, the integration can reduce time-consuming manual coordination between security and recovery teams. Earlier this year Commvault integrated https://www.blocksandfiles.com/security/2026/02/25/commvault-plugs-ai-anomaly-alerts-into-crowdstrike-falcon-siem/4092058 its AI-powered anomaly alerts and other security capabilities into CrowdStrike software to enable faster, more precise responses to cybersecurity events. And Commvault integrated https://www.blocksandfiles.com/data-protection/2025/04/29/commvault-expands-cleanroom-recovery-and-crowdstrike-partnership/1601730? gl=1 1sipwx2 ga MTY2OTcyMjAyNS4xNzcwODg2MTMy ga NSDTXHMMN0 czE3NzIwMDc1NzkkbzQ0JGcxJHQxNzcyMDA4MjgzJGo2MCRsMCRoMA.. CrowdStrike's malware-detecting Falcon XDR into its Commvault Cloud https://blocksandfiles.com/2024/10/08/commvault-shift-announcements/ in January last year. Commvault is a platinum sponsor of Fal.Con 2026, lower than, in order, Pinnacle, Premier, and Diamond sponsors, but higher than Gold, Silver, Innovator and LATAM ones. Rubrik CrowdStrike and Rubrik https://www.blocksandfiles.com/data-protection/2026/08/28/rubrik-revenues-roar-ahead/5293217 say they are providing closed-loop agentic identity resilience workflows to recover from identity-based attacks at machine speed. The two will provide security teams with a complete, agentic identity resilience workflow orchestrated by Charlotte Agentic SOAR. This combines real-time threat detection and response from Falcon Next-Gen Identity Security with automated data and identity protection with Rubrik Identity Resilience. The two say organizations can now detect, investigate, and recover from compromised identity environments in hours rather than days. Daniel Bernard, Chief Business Officer at CrowdStrike, said: "By bringing CrowdStrike and Rubrik together via agentic workflows, we're empowering organizations to contain and recover from identity-based attacks faster than ever.” Anneka Gupta, Rubrik’s Chief Product Officer, said: “We integrated Rubrik and CrowdStrike because you can't fight rapid AI threats with manual workflows. You need automated, intelligent defense to shut down active attacks instantly and guarantee a clean, fast recovery.” An example of what the integration can bring is that CrowdStrike detects and contains malicious activity, while Rubrik correlates detection data with identity activity logs. Context within Human Resources Information Systems HRIS and IGA solutions can be scanned for threats across backup data. Teams can then surgically undo malicious Active Directory changes or trigger automated AD forest recovery plans while removing malicious files. From detection to recovery, The incident is detected, a response initiated, and then closed with minimal manual intervention. Rubrik says this announcement builds on the existing identity-forward integrations that Rubrik supports from CrowdStrike, including Falcon Next-Gen SIEM, Charlotte Agentic SOAR, Falcon Next-Gen Identity Security, and Threat Intelligence. The company is a Premier sponsor of Fal.Con 2026. VAST Data Bernard said: “AI is reshaping the enterprise, and security has to extend everywhere AI operates. By bringing CrowdStrike into the VAST AI Operating System, we’re extending Falcon protection across the infrastructure, data and AI pipelines powering the next generation of enterprise AI. VAST Data is one of the most innovative AI infrastructure software companies on the market – secured by CrowdStrike.” VAST Data’s https://www.blocksandfiles.com/ai-ml/2026/07/15/vast-data-and-cloudera-offer-combined-ai-factory/5271629 AI Operating System natively supports CrowdStrike’s Falcon sensor, bringing CrowdStrike protection directly into the VAST environment. VAST audit telemetry will integrate directly with CrowdStrike Falcon Next-Gen SIEM, combining detailed visibility into how users and machines access enterprise data with CrowdStrike’s threat intelligence and detection capabilities. Security teams will be able to correlate activity across the VAST AI OS with the broader cyber environment to identify anomalous behavior, investigate incidents and better understand the scope of potential threats. This establishes a foundation for deeper integrations with Falcon Guardian, CrowdStrike’s new AI Detection and Response AIDR offering. Falcon Guardian will integrate with VAST InsightEngine, leveraging the Nvidia AI Data Platform reference design, to bring threat detection into the pipelines preparing enterprise data for AI. As InsightEngine ingests, processes and enriches data for AI knowledge bases and workflows, organisations will be able to use Guardian to identify sensitive or risky information, and surface potentially harmful activity before it reaches downstream AI systems. CrowdStrike can detect threats such as prompt injection, jailbreak attempts and other malicious activity, helping organisations identify risk across both the data feeding AI and the activity around it. Renen Hallak, Founder & CEO at VAST Data, said: “The security boundary for AI can’t stop at the infrastructure. Enterprises need to understand who is accessing their data, how that data is moving through AI pipelines and what is happening when applications and models interact with it. Together with CrowdStrike, we’re bringing security across each of those layers. By combining the VAST AI Operating System with the intelligence of the Falcon platform, customers can build AI environments where security is part of the architecture from the foundation through the AI pipeline.” VAST Data is a Gold-level sponsor of Fal.Con 2026. Comment We wonder that a Charlotte Agentic SOAR integration has not been announced between CrowdStrike and Cohesity https://www.blocksandfiles.com/ai-ml/2026/06/18/cohesity-goes-agentic-with-headless-protection/5258151 , a Silver-level Fal.Con 2026 sponsor. There are existing integrations between Cohesity DataHawk and CrowdStrike’s Falcon LogScale to pushes security signals from secondary data into Falcon. Also CrowdStrike Falcon Adversary Intelligence feeds are imported into Cohesity’s Data Cloud threat library. It is surprising that Cohesity and CrowdStrike are not replicating the latest Commvault and Rubrik CrowdStrike agent level integrations. Veeam https://www.blocksandfiles.com/ai-ml/2026/07/27/how-can-you-trust-ai-agents-veeam-can-help/5279043 is also behind the curve here. It and CrowdStrike partnered in April last year to put Veeam Data Platform events into Falcon LogScale and Falcon Next-Gen SIEM. This is a 1-way deal in contrast to the 2-way Cohesity-Commvault deal. We are surely going to see CrowdStrike agentic AI-level integrations for Cohesity and Veeam in the relatively near future. Availability The integration between Commvault and Charlotte Agentic SOAR is generally available for joint Commvault and CrowdStrike customers. The integration is also available through the CrowdStrike Marketplace https://marketplace.crowdstrike.com/listings/commvault-cloud-response-actions/ . There is no availability date for the Rubrik-CrowdStrike Charlotte Agentic SOAR integration. Native CrowdStrike Falcon sensor support for VAST Data is certified and available today. VAST integrations with CrowdStrike Falcon Next-Gen SIEM and Falcon Guardian are available in private preview. Learn more here https://www.vastdata.com/partners/crowdstrike .