CrowdStrike and Rubrik Automate Identity Attack Recovery at Fal.Con 2026
CrowdStrike and Rubrik have announced a joint agentic workflow for identity attack resilience, unveiled at CrowdStrike's Fal.Con conference in Las Vegas on 1 September 2026. The integration is designed to let security teams detect, investigate and recover from a compromised identity environment in hours rather than days.
Key takeaways
- Three products are linked into one automated loop: Falcon Next-Gen Identity Security for detection and containment, Rubrik Identity Resilience for restoring identity data, and Charlotte Agentic SOAR for orchestration.
- The workflow can automatically reverse unauthorised changes to Active Directory, running either targeted remediation or a full forest recovery.
- The stated outcome is recovery in hours rather than days, with recovery time objective (RTO) as the headline metric.
- Rubrik Zero Labs research cited alongside the announcement found 90% of IT and security leaders name identity-based attacks as their most significant threat.
- Rubrik is one of several recovery vendors being wired into CrowdStrike's agentic workflows, alongside Commvault and VAST Data.
What was announced
Three products are linked into a single automated loop. CrowdStrike Falcon Next-Gen Identity Security detects and contains identity threats in real time. Rubrik Identity Resilience restores identity data and directory state after an attack. Charlotte Agentic SOAR, CrowdStrike's AI orchestration layer, sequences the two so detection, investigation and recovery run end to end without manual handoff. SOAR stands for security orchestration, automation and response.
The workflow can automatically reverse unauthorised changes to Active Directory, the service that stores employee accounts and access permissions in most large enterprises. Teams can run targeted remediation or a full forest recovery, with the stated aim of cutting recovery time objective (RTO).
Daniel Bernard, Chief Business Officer at CrowdStrike, said the partnership lets organisations “contain and recover from identity-based attacks faster than ever.” Anneka Gupta, Chief Product Officer at Rubrik, described reliance on human reaction time as risky and obsolete when a breach unfolds in milliseconds.
The companies cited research from Rubrik Zero Labs finding that 90% of IT and security leaders regard identity-based attacks as the most significant threat to their organisation. Rubrik is one of several recovery vendors being wired into CrowdStrike's agentic workflows, alongside Commvault and VAST Data, and the integration extends a partnership between the two companies that began in 2025.
What it means for the identity industry
The substance here sits in workforce identity, the employee and service accounts inside a company's directory, which is a different stack from customer identity with different buyers and different budgets. What carries across is the reframing: identity is no longer treated as a fact established once and filed away, but as a state that can be corrupted at machine speed and therefore has to be continuously watched and quickly restored, with time to a clean state as the metric that follows. That pressure does not stop at the corporate perimeter. Customer-facing verification still largely rests on a decision made once at signup and trusted indefinitely afterwards, and whether that assumption survives the same AI acceleration is an open question the security side has already answered for itself.
Frequently asked questions
What did CrowdStrike and Rubrik announce at Fal.Con 2026?
A joint agentic workflow for identity attack resilience, announced on 1 September 2026. It combines CrowdStrike Falcon Next-Gen Identity Security, Rubrik Identity Resilience and CrowdStrike's Charlotte Agentic SOAR into a closed loop covering detection, investigation and recovery of compromised identity environments.
What is Charlotte Agentic SOAR?
It is CrowdStrike's AI orchestration layer. SOAR stands for security orchestration, automation and response. In this integration it sequences detection and recovery actions across both vendors' products so an incident can run end to end without a manual handoff between tools.
What is Active Directory forest recovery?
Active Directory is the service that stores employee accounts and access permissions in most large enterprises. A forest is the top-level container of one or more directory domains. Forest recovery restores that entire structure to a known good state, as opposed to targeted remediation, which reverses only specific unauthorised changes.
Is workforce identity the same as customer identity verification?
No. Workforce identity covers employee, contractor and service accounts inside an organisation's own directory, and is typically bought by security teams. Customer identity verification covers how a person proves who they are when opening an account with a business, and is typically bought by product, growth or compliance teams. They are separate stacks with separate budgets.
What does recovery time objective (RTO) mean?
Recovery time objective is the maximum acceptable time between a disruption and the restoration of normal service. In this announcement it is the metric the integration is aimed at reducing, by shortening the interval between an identity compromise being detected and the environment being returned to a clean state.
Related reading
- Synthetic identity and injection attacks in 2026
- Why biometrics alone are no longer enough
- Proof of human: bot detection at the login layer
Sources: Business Wire press release, 1 September 2026; Blocks & Files reporting on CrowdStrike recovery integrations, 2 September 2026; Rubrik Zero Labs identity threat research.




.png)