News
Rubrik, CrowdStrike Link Agentic SOAR to Identity Recovery
Rubrik and CrowdStrike have announced an expanded identity-security integration intended to move compromised identity environments from threat detection through clean recovery with less manual intervention. The workflow combines CrowdStrike Falcon Next-Gen Identity Security with Rubrik Identity Resilience and uses CrowdStrike's Charlotte Agentic SOAR as the orchestration layer.
The companies announced the integration Sept. 1 at Fal.Con 2026 in Las Vegas. According to Rubrik's announcement, CrowdStrike supplies real-time threat detection and response while Rubrik supplies data and identity protection and recovery. Rubrik said the combined workflow is intended to let security teams detect, investigate and recover compromised identity environments in hours rather than days.
The deal expands on an existing integration between the two vendors. Rubrik previously made a CrowdStrike integration for identity-event correlation and surgical rollback generally available in December 2025. The new announcement adds agentic orchestration through Charlotte Agentic SOAR and describes a broader closed-loop workflow spanning detection, containment, investigation and recovery.
How the Closed-Loop Workflow Operates
Rubrik describes the new integration as a closed-loop response process. CrowdStrike detects and contains malicious activity, while Rubrik correlates CrowdStrike detection data with identity activity logs. Rubrik said that context from Human Resources Information Systems and identity governance and administration systems can also be scanned for threats across backup data.
From there, the recovery side can target identity changes rather than requiring only a broad restore. Rubrik said teams can surgically reverse malicious Active Directory changes, remove malicious files or initiate automated Active Directory forest recovery plans. The company said the incident can then be closed with minimal manual intervention.
The Active Directory rollback mechanism builds on functionality Rubrik documented when the earlier CrowdStrike integration became generally available. In that implementation, Rubrik Identity Resilience polls CrowdStrike Falcon Next-Gen Identity Security APIs for identity-based events. Rubrik then ingests those events and correlates them with actions already collected from the identity environment. An administrator can select a compromised identity and choose whether to roll back all associated actions or selected actions. Rubrik said reversions use an API call to Rubrik Backup Service, which makes an LDAP call to Active Directory.
Charlotte Agentic SOAR Supplies the Orchestration Layer
CrowdStrike introduced Charlotte Agentic SOAR in November 2025 as the orchestration layer of its Falcon Agentic Security Platform. CrowdStrike says the product coordinates native, custom-built and third-party AI-powered agents across security workflows while keeping them under analyst control.
On its Charlotte Agentic SOAR product page, CrowdStrike describes the service as combining structured automation with agentic reasoning. Analysts can define intent and guardrails, while agents can collaborate, reason and act in real time. CrowdStrike also says teams can use natural language with Charlotte AI AgentWorks to design, test and deploy customized agents across the Falcon platform and connected security products.
For the Rubrik integration, the significance of that orchestration layer is the connection between CrowdStrike's detection and containment functions and Rubrik's recovery operations. The new deal identifies four CrowdStrike technologies that already participate in Rubrik's identity-focused integrations: Falcon Next-Gen SIEM, Charlotte Agentic SOAR, Falcon Next-Gen Identity Security and CrowdStrike Threat Intelligence.
Identity Detection Meets Recovery
Falcon Next-Gen Identity Security is CrowdStrike's identity-security component in the new workflow. CrowdStrike says the product continuously evaluates identity risk and can enforce access controls across human, non-human and AI identities. Its documented functions include identifying overprivileged access and attack paths, applying just-in-time access, revoking access during a session, triggering multifactor authentication and detecting lateral movement.
Rubrik's side of the integration centers on Rubrik Identity Resilience. Rubrik currently lists Active Directory, Microsoft Entra ID and Okta among the identity environments covered by the product. Its documented capabilities include immutable backups, recovery of compromised identity environments, removal of attacker persistence and replaying legitimate identity changes after recovery. The Sept. 1 announcement's concrete remediation examples specifically cite malicious Active Directory changes and Active Directory forest recovery.
Rubrik expanded that product earlier this year with Identity Roll Forward and Identity Continuity. A June 9 announcement said Identity Roll Forward was designed to identify, isolate and reverse unauthorized Active Directory changes while keeping legitimate changes intact. Identity Continuity, stemming from Rubrik's acquisition of Strata.io, was described as automatically failing authentication over to a secondary identity provider while recovery proceeds.
Identity Attacks Drive the Integration
Rubrik tied the announcement to research from Rubrik Zero Labs and Wakefield Research. The Identity Crisis report surveyed 1,625 IT and security leaders globally. Ninety percent of respondents agreed that identity-based attacks represent the single largest threat to their organizations.
The same report said 89% of respondents had fully or partially incorporated AI agents into their identity infrastructure, while 58% estimated that within the next year at least half of the cyberattacks they face would be driven by agentic AI. Rubrik also reported that 54% of respondents relied on processes requiring manual recovery procedures.
Rubrik's stated benefit for the CrowdStrike integration is a reduction in recovery time objective from days to hours. It attributes that change to connecting detection, investigation and containment directly to recovery operations rather than handing incidents between separate security and IT workflows. The company also lists reduced console switching, targeted remediation and removal of attacker persistence among the intended benefits.
About the Author
David Ramel is an editor and writer at Converge 360.