Rubrik, VAST Data, Commvault and Sublime Security unveiled new integrations with CrowdStrike at Fal.Con 2026, extending the Falcon ecosystem across identity resilience, AI infrastructure, cyber recovery and email security.
The announcements reflect CrowdStrike’s push to make Falcon a broader security operations layer, with partners connecting recovery, data protection and threat telemetry directly into workflows such as Charlotte Agentic SOAR and Falcon Next-Gen SIEM.
Rubrik brings identity recovery into CrowdStrike workflows
Rubrik, a security and AI operations company, was among the organizations that made a key announcement during the conference.
It announced that it would be partnering with CrowdStrike to deliver security teams a complete, agentic identity resilience workflow orchestrated by Charlotte Agentic SOAR – a unified workspace that combines AI agents, rule-based workflows, and custom applications to automate and govern security operations in real time.
“As adversaries weaponize AI and a breach unfolds in milliseconds, relying on human reaction time is risky and obsolete,” said Anneka Gupta, Chief Product Officer, Rubrik. “We integrated Rubrik and CrowdStrike because you can’t fight rapid AI threats with manual workflows. You need automated, intelligent defense to shut down active attacks instantly and guarantee a clean, faster recovery.”
Among the benefits of the CrowdStrike and Rubrik Identity Resilience include:
- Complete agentic incident response: Consolidates detection, containment, investigation, and recovery into a unified workflow driven by both companies.
- Unified security and IT workflows: Removes console switching and tool friction between security and IT operations.
- Surgical remediation and clean recovery: Reverses unauthorized Active Directory changes, removes malicious files, or executes complete forest recoveries.
- Reduce RTO: Recovers IdPs cleanly and removes attacker persistence. Ensures identity incidents are resolved in hours, not days.
VAST Data targets security for enterprise AI infrastructure
AI operating system company, VAST Data, has announced new integrations with CrowdStrike that will provide enterprise-grade cybersecurity across the infrastructure, data, and AI workloads that support production AI.
VAST’s AI infrastructure platform natively supports the CrowdStrike Falcon sensor and integrates with Falcon Next-Gen SIEM and CrowdStrike’s new Falcon AI Detection and Response (AIDR) solution across the VAST AI Operating System (OS).
“The security boundary for AI can’t stop at the infrastructure. Enterprises need to understand who is accessing their data, how that data is moving through AI pipelines, and what is happening when applications and models interact with it,” said Renen Hallak, Founder and CEO at VAST Data.
“Together with CrowdStrike, we’re bringing security across each of those layers. By combining the VAST AI Operating System with the intelligence of the Falcon platform, customers can build AI environments where security is part of the architecture from the foundation through the AI pipeline,” added Hallak.
This integration is meant to:
- Protect the infrastructure powering AI: The VAST AI OS is integrating its data infrastructure platforms with native support for the Falcon sensor to bring CrowdStrike protection directly into the VAST environments supporting mission-critical enterprise AI workloads.
- Turning data access telemetry into actionable security intelligence: VAST audit telemetry will integrate directly with CrowdStrike Falcon Next-Gen SIEM, allowing security teams to correlate activity across the VAST AI OS to identify anomalous behavior, investigate incidents, and better understand the scope of potential threats.
- Embed AI-native protection directly into data pipelines: Falcon AIDR will integrate with VAST InsightEngine to leverage the NVIDIA AI Data Platform, bringing threat detection into pipelines that prepare enterprise data for AI. Organizations will be able to use Falcon AIDR to identify sensitive or risky information and surface harmful activity before it reaches downstream AI systems.
Commvault connects cyber recovery with Charlotte Agentic SOAR
Commvault, a provider of unified resilience at enterprise scale, announced a new integration with CrowdStrike, making its cyber recovery actions available as native steps within Charlotte Agentic SOAR workflows.
Joint customers will be able to automate Commvault recovery actions as part of security workflows, accelerating response and forensic investigations while reducing manual coordination between security and recovery teams.
Further, this connector helps security teams incorporate Commvault cyber recovery actions directly into workflows orchestrated by Charlotte Agentic SOAR, accelerating investigation, response, and recovery.
“Security and recovery teams need to move quickly and in coordination during an incident,” said Vidya Shankaran, Field CTO, Commvault. “Our integration with CrowdStrike Charlotte Agentic SOAR makes Commvault cyber recovery actions available directly within security workflows, helping joint customers reduce manual handoffs and accelerate investigation and response.”
“This strengthens cyber resilience and simplifies how security and recovery teams work together seamlessly,” adds Shankaran.
Sublime Security feeds email telemetry into Falcon SIEM
Agentic email security platform Sublime Security announced a new integration that enables Sublime Security’s email security signals to flow into CrowdStrike Falcon Next-Gen SIEM.
Security teams will be able to correlate Sublime’s email security data with endpoint, identity, cloud, threat intelligence, and other security telemetry during investigations, thanks to the integration.
Further, security teams can incorporate email context into broader investigations and security operations workflows by making these signals available within Falcon Next-Gen SIEM.
“Finding a novel attack is only half the job. Security teams need the ability to act on it immediately,” said Josh Kamdjou, CEO and co-founder of Sublime Security. “By making Sublime’s email security signals available within CrowdStrike Falcon Next-Gen SIEM, analysts can connect email activity with broader security telemetry while quickly adapting email detection coverage as new threats emerge.”





