Rubrik and CrowdStrike Bring Agentic Automation to Identity Attack Resilience
Providing closed-loop agentic identity resilience workflows to recover from identity-based attacks at machine speed
This is a Press Release edited by StorageNewsletter.com on September 4, 2026 at 2:00 pmRubrik, a security and AI operations company, announced that Rubrik and CrowdStrike will deliver security teams with a complete, agentic identity resilience workflow orchestrated by Charlotte Agentic SOAR.
By combining real-time threat detection and response from CrowdStrike Falcon Next-Gen Identity Security with automated data and identity protection with Rubrik Identity Resilience, organizations can now detect, investigate, and recover from compromised identity environments in hours rather than days. By expediting the transition from threat detection to clean recovery, this integration frees security teams to focus on strategic initiatives.
“Our long-standing partnership with Rubrik has always been about giving joint customers the best of both worlds. Today we execute on the next phase,” said Daniel Bernard, CBO, CrowdStrike. “By bringing CrowdStrike and Rubrik together via agentic workflows, we’re empowering organizations to contain and recover from identity-based attacks faster than ever.”
As Identity Attacks Surge, Rapid Recoverability Becomes Non-Negotiable
Recent data from Rubrik Zero Labs found that 90% of IT and security leaders agree that identity-based attacks represent the single largest threat to their organizations.
“As adversaries weaponize AI and a breach unfolds in milliseconds, relying on human reaction time is risky and obsolete,” said Anneka Gupta, CPO, Rubrik. “We integrated Rubrik and CrowdStrike because you can’t fight rapid AI threats with manual workflows. You need automated, intelligent defense to shut down active attacks instantly and guarantee a clean, fast recovery.”
The integration establishes a closed-loop response. CrowdStrike detects and contains malicious activity, while Rubrik correlates detection data with identity activity logs. For example, context within Human Resources Information Systems (HRIS) and IGA solutions can be scanned for threats across backup data. Teams can then surgically undo malicious Active Directory changes or trigger automated forest recovery plans while removing malicious files. From detection to recovery, the incident is then closed with minimal manual intervention.
Key Benefits of CrowdStrike and Rubrik Identity Resilience
- Complete Agentic Incident Response: Consolidates detection, containment, investigation, and recovery into a unified workflow driven by CrowdStrike and Rubrik
- Unified Security and IT Workflows: Removes console switching and tool friction between security and IT operations
- Surgical Remediation and Clean Recovery: Reverses unauthorized Active Directory changes, removes malicious files, or executes complete forest recoveries
- Reduce RTO from Days to Hours: Recovers IdPs fast and clean, and removes attacker persistence. Ensures identity incidents are resolved, not just managed
This announcement builds on the existing identity-forward integrations that Rubrik supports today from CrowdStrike, including Falcon Next-Gen SIEM, Charlotte Agentic SOAR, Falcon Next-Gen Identity Security, and Threat Intelligence enabling joint customers to recover their IdPs to clean and current states.













