CrowdStrike Fal.Con 2026 Brings New Security Integrations

CrowdStrike Fal.Con 2026 brought new integrations with Rubrik, VAST Data, Commvault and Sublime Security across AI, identity and cyber recovery.

Written By
Jordan Smith
Jordan Smith
Sep 9, 2026
4 minute read
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Rubrik, VAST Data, Commvault and Sublime Security unveiled new integrations with CrowdStrike at Fal.Con 2026, extending the Falcon ecosystem across identity resilience, AI infrastructure, cyber recovery and email security.

The announcements reflect CrowdStrike’s push to make Falcon a broader security operations layer, with partners connecting recovery, data protection and threat telemetry directly into workflows such as Charlotte Agentic SOAR and Falcon Next-Gen SIEM.

Rubrik brings identity recovery into CrowdStrike workflows

Rubrik, a security and AI operations company, was among the organizations that made a key announcement during the conference.

It announced that it would be partnering with CrowdStrike to deliver security teams a complete, agentic identity resilience workflow orchestrated by Charlotte Agentic SOAR – a unified workspace that combines AI agents, rule-based workflows, and custom applications to automate and govern security operations in real time.

“As adversaries weaponize AI and a breach unfolds in milliseconds, relying on human reaction time is risky and obsolete,” said Anneka Gupta, Chief Product Officer, Rubrik. “We integrated Rubrik and CrowdStrike because you can’t fight rapid AI threats with manual workflows. You need automated, intelligent defense to shut down active attacks instantly and guarantee a clean, faster recovery.”

Among the benefits of the CrowdStrike and Rubrik Identity Resilience include:

  • Complete agentic incident response: Consolidates detection, containment, investigation, and recovery into a unified workflow driven by both companies.
  • Unified security and IT workflows: Removes console switching and tool friction between security and IT operations.
  • Surgical remediation and clean recovery: Reverses unauthorized Active Directory changes, removes malicious files, or executes complete forest recoveries.
  • Reduce RTO: Recovers IdPs cleanly and removes attacker persistence. Ensures identity incidents are resolved in hours, not days.
Advertisement

VAST Data targets security for enterprise AI infrastructure

AI operating system company, VAST Data, has announced new integrations with CrowdStrike that will provide enterprise-grade cybersecurity across the infrastructure, data, and AI workloads that support production AI.

VAST’s AI infrastructure platform natively supports the CrowdStrike Falcon sensor and integrates with Falcon Next-Gen SIEM and CrowdStrike’s new Falcon AI Detection and Response (AIDR) solution across the VAST AI Operating System (OS).

“The security boundary for AI can’t stop at the infrastructure. Enterprises need to understand who is accessing their data, how that data is moving through AI pipelines, and what is happening when applications and models interact with it,” said Renen Hallak, Founder and CEO at VAST Data.

“Together with CrowdStrike, we’re bringing security across each of those layers. By combining the VAST AI Operating System with the intelligence of the Falcon platform, customers can build AI environments where security is part of the architecture from the foundation through the AI pipeline,” added Hallak.

This integration is meant to:

  • Protect the infrastructure powering AI: The VAST AI OS is integrating its data infrastructure platforms with native support for the Falcon sensor to bring CrowdStrike protection directly into the VAST environments supporting mission-critical enterprise AI workloads.
  • Turning data access telemetry into actionable security intelligence: VAST audit telemetry will integrate directly with CrowdStrike Falcon Next-Gen SIEM, allowing security teams to correlate activity across the VAST AI OS to identify anomalous behavior, investigate incidents, and better understand the scope of potential threats.
  • Embed AI-native protection directly into data pipelines: Falcon AIDR will integrate with VAST InsightEngine to leverage the NVIDIA AI Data Platform, bringing threat detection into pipelines that prepare enterprise data for AI. Organizations will be able to use Falcon AIDR to identify sensitive or risky information and surface harmful activity before it reaches downstream AI systems.
Advertisement

Commvault connects cyber recovery with Charlotte Agentic SOAR

Commvault, a provider of unified resilience at enterprise scale, announced a new integration with CrowdStrike, making its cyber recovery actions available as native steps within Charlotte Agentic SOAR workflows.

Joint customers will be able to automate Commvault recovery actions as part of security workflows, accelerating response and forensic investigations while reducing manual coordination between security and recovery teams.

Further, this connector helps security teams incorporate Commvault cyber recovery actions directly into workflows orchestrated by Charlotte Agentic SOAR, accelerating investigation, response, and recovery.

“Security and recovery teams need to move quickly and in coordination during an incident,” said Vidya Shankaran, Field CTO, Commvault. “Our integration with CrowdStrike Charlotte Agentic SOAR makes Commvault cyber recovery actions available directly within security workflows, helping joint customers reduce manual handoffs and accelerate investigation and response.”

“This strengthens cyber resilience and simplifies how security and recovery teams work together seamlessly,” adds Shankaran.

Sublime Security feeds email telemetry into Falcon SIEM

Agentic email security platform Sublime Security announced a new integration that enables Sublime Security’s email security signals to flow into CrowdStrike Falcon Next-Gen SIEM.

Security teams will be able to correlate Sublime’s email security data with endpoint, identity, cloud, threat intelligence, and other security telemetry during investigations, thanks to the integration.

Further, security teams can incorporate email context into broader investigations and security operations workflows by making these signals available within Falcon Next-Gen SIEM.

“Finding a novel attack is only half the job. Security teams need the ability to act on it immediately,” said Josh Kamdjou, CEO and co-founder of Sublime Security. “By making Sublime’s email security signals available within CrowdStrike Falcon Next-Gen SIEM, analysts can connect email activity with broader security telemetry while quickly adapting email detection coverage as new threats emerge.”

Jordan Smith

Jordan Smith is an enterprise technology and cybersecurity journalist with nearly a decade of experience covering B2B IT, federal technology, artificial intelligence, cybersecurity, cloud computing, and emerging digital trends. His reporting helps business and technology leaders understand how new technologies, security challenges, and infrastructure decisions affect modern organizations. Jordan has reported on enterprise and public-sector technology for TechnologyAdvice, HCLTech, MeriTalk, and Channel Insider. His background spans cybersecurity, cloud infrastructure, AI adoption, digital transformation, and federal IT initiatives, giving him a broad perspective on the tools, policies, and innovations shaping today’s technology landscape. Before joining TechnologyAdvice, Jordan served as a Senior Technology Reporter at MeriTalk, where he covered the federal IT space, and later worked as a US Regional Reporter and Copy Editor/Writer for HCLTech. His experience across reporting, copyediting, podcasting, and event moderation allows him to translate complex technical topics into clear, timely, and useful insights for business audiences. Jordan holds a Master of Arts in Journalism from the University of Nebraska–Lincoln and a Bachelor of Science in Criminal Justice and Psychology from Edgewood University. Through his work, he helps readers stay informed about cybersecurity developments, enterprise technology trends, and the business impact of emerging IT solutions.

Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.