Executive Overview
In the modern enterprise threat landscape, identity has rapidly become the ultimate perimeter—and consequently, the primary target for sophisticated adversaries. When malicious actors compromise credentials, elevate privileges, or laterally move through directory services like Active Directory (AD), the resulting disruption can paralyze business operations for days, weeks, or even months. Traditional incident response frameworks, hampered by fragmented tooling and siloed remediation processes, often force security operations center (SOC) analysts to manually parse through massive logs, isolate compromised systems, and piece together directory modifications. This laborious sequence routinely stretches identity recovery timelines from hours into days.
To fundamentally transform this paradigm, cybersecurity leaders Rubrik and CrowdStrike have announced a significant expansion of their strategic technology partnership. The collaboration introduces an advanced, closed-loop identity-security integration designed to bridge the traditionally disparate worlds of real-time threat detection and immutable data recovery. By combining the strengths of CrowdStrike Falcon Next-Gen Identity Security and Rubrik Identity Resilience—and orchestrating the entire lifecycle through CrowdStrike’s recently launched Charlotte Agentic SOAR (Security Orchestration, Automation, and Response)—the two companies are delivering a unified workflow that drastically shrinks recovery timelines.
Rather than relying on manual intervention or broad, disruptive system-wide restores, this new integration leverages autonomous agentic reasoning and surgical rollback mechanisms. Security teams can now detect, investigate, contain, and remediate compromised identity environments in a fraction of the time previously required. This comprehensive report explores the operational mechanics of the closed-loop workflow, the integration of agentic orchestration, the historical context of the partnership, and the broader implications for enterprise cybersecurity postures.
Detailed Chronology of the Integration
The path toward a fully automated, closed-loop identity recovery framework represents a deliberate evolution in how Rubrik and CrowdStrike have aligned their architectural capabilities. Understanding the velocity of this technological convergence requires examining the timeline of product milestones that culminated in this latest announcement.
The Foundation: Identity-Event Correlation and Surgical Rollback (December 2025)
The groundwork for the current expanded integration was formally laid in December 2025, when Rubrik generally released an initial integration centered on identity-event correlation and surgical rollback. Prior to this release, security teams faced a profound visibility gap between endpoint/identity telemetry and backup/recovery state data.

In that foundational implementation, Rubrik Identity Resilience was engineered to poll APIs from CrowdStrike Falcon Next-Gen Identity Security continuously. When CrowdStrike flagged suspicious or malicious identity-based events, Rubrik ingested those telemetry streams and correlated them directly with historical actions already harvested from the enterprise identity environment.
Crucially, this integration moved beyond binary "all-or-nothing" system restorations. Instead, it introduced granular visibility: an administrator could select a compromised identity account and choose whether to roll back all associated malicious modifications or execute targeted, surgical reversions on specific actions. These reversions were executed via API calls to the Rubrik Backup Service, which in turn initiated LDAP calls to Active Directory to strip away unauthorized alterations without resetting legitimate user progress or wiping entire server states.
The Leap to Agentic Automation (Current Announcement)
Building directly upon the December 2025 foundation, the newly announced expansion elevates the partnership from reactive correlation and manual administrative choices to fully orchestrated, closed-loop automation.
While the previous iteration required human oversight to select rollback parameters and execute remediation steps, the updated workflow integrates CrowdStrike’s Charlotte Agentic SOAR as an intelligent orchestration layer. This addition transforms the integration from a cooperative toolset into an autonomous response mechanism. The system can now seamlessly span the entire incident lifecycle—moving from initial threat detection and containment to automated investigation, contextual enrichment, surgical rollback, and final incident closure—with minimal human friction.
How the Closed-Loop Workflow Operates
To fully appreciate the efficiency gains promised by the Rubrik and CrowdStrike integration, it is necessary to examine the technical mechanics of the closed-loop response process step-by-step.

1. Detection and Containment
The lifecycle begins at the perimeter of identity infrastructure. CrowdStrike Falcon Next-Gen Identity Security continuously monitors identity behaviors, session tokens, authentication attempts, and directory traffic in real time. When anomalous behaviors or known attack patterns—such as Golden Ticket attacks, DCShadow, or abnormal privilege escalations—are identified, CrowdStrike instantly flags and contains the malicious activity, preventing further lateral movement within the network.
2. Contextual Correlation and Threat Scanning
Simultaneously, Rubrik ingests CrowdStrike’s detection data and correlates it against deep identity activity logs. However, the workflow extends even deeper by integrating secondary contextual data sources. According to Rubrik’s technical documentation, the system can scan backup data for hidden persistence mechanisms, analyzing context derived from:
- Human Resources Information Systems (HRIS): To verify employment statuses, department transfers, or unusual offboarding anomalies that might manifest as dormant account exploits.
- Identity Governance and Administration (IGA) Systems: To cross-reference authorized role assignments against active directory permissions.
By pulling data from backups and auxiliary identity governance sources, the platform ensures that secondary persistence vectors—such as backdoors planted in historical snapshots—are accounted for during the investigation phase.
3. Surgical Remediation and Active Directory Forest Recovery
Once the exact scope of the compromise has been mapped, the recovery phase initiates. Rather than enforcing a blunt-force, wholesale restoration of Active Directory from a previous point in time—which often results in massive data loss, dropped authentication sessions, and operational downtime—the platform executes precise corrections.
Security teams, guided by agentic recommendations, can:

- Surgically reverse malicious Active Directory attribute changes.
- Systematically remove planted malicious files.
- Initiate automated, pre-configured Active Directory forest recovery plans when widespread structural compromise is detected.
By targeting only the unauthorized identity modifications, the enterprise preserves legitimate operational continuity. Once these surgical reversions are complete, the system validates the environment’s integrity and automatically closes the incident ticket with minimal manual intervention required from overextended SOC analysts.
Charlotte Agentic SOAR: The Orchestration Layer
A critical differentiator in this expanded partnership is the incorporation of CrowdStrike’s Charlotte Agentic SOAR, introduced in November 2025 as the flagship orchestration engine of the Falcon Agentic Security Platform.
Bridging Structured Automation and Agentic Reasoning
Traditional SOAR platforms have long relied on rigid, human-authored playbooks. While effective against known, highly predictable threat vectors, legacy SOAR solutions frequently break down when confronted with novel, multi-stage attacks that require real-time adaptation and contextual judgment.
Charlotte Agentic SOAR addresses this limitation by marrying structured automation with advanced agentic reasoning. Within the Rubrik-CrowdStrike integration, Charlotte acts as the cognitive core that coordinates native, custom-built, and third-party AI-powered agents across diverse security domains.
Key operational capabilities of Charlotte Agentic SOAR within this workflow include:

- Real-Time Collaboration: AI-powered agents communicate across the CrowdStrike Falcon platform and Rubrik Identity Resilience, sharing telemetry and proposing remediation strategies without waiting for human prompts.
- Analyst Guardrails: While agents possess autonomous reasoning capabilities, human analysts retain ultimate authority by defining operational intent, risk thresholds, and execution guardrails.
- Natural Language Customization: Through CrowdStrike AI AgentWorks, security teams can leverage natural language prompts to design, test, and deploy customized agents tailored to their specific enterprise policies and directory structures.
By routing the identity recovery workflow through Charlotte Agentic SOAR, the partnership eliminates the swivel-chair effect that typically plagues incident responders, replacing fragmented tool management with unified, autonomous orchestration.
Supporting Context, Metrics, and Market Impact
The urgency behind automating identity recovery is underscored by prevailing cybersecurity metrics regarding identity-driven breaches. According to numerous industry threat reports, over 80% of modern cyberattacks leverage compromised credentials or exploit directory services vulnerabilities to achieve initial access and persist within corporate networks.
When an adversary successfully compromises Active Directory or cloud-based identity providers (such as Microsoft Entra ID), they effectively hold the keys to the kingdom. Historically, recovering a compromised Active Directory forest could take days or weeks of painstaking manual work, costing enterprises millions in downtime, forensic investigations, and lost revenue.
By compressing this timeline from days to hours, the Rubrik and CrowdStrike integration addresses the single largest bottleneck in incident response: the time-to-recovery (TTR) metric. In high-stakes ransomware incidents—where attackers frequently compromise identity layers before deploying encryption payloads—rapid, surgical identity restoration can mean the difference between a minor operational hiccup and a catastrophic enterprise-wide shutdown.
Future Outlook
As cyber adversaries increasingly leverage artificial intelligence and automated toolsets to accelerate their attack lifecycles, the defense community must respond with an equivalent level of technological sophistication. Manual incident response and siloed security tools are no longer viable strategies for safeguarding complex, hybrid enterprise environments.

The expanded integration between Rubrik and CrowdStrike signals a broader industry trend toward hyper-automation and vendor ecosystem convergence. By fusing real-time endpoint and identity telemetry with immutable data resilience, and powering that bridge with agentic AI orchestration, the two companies have established a new benchmark for identity attack resilience.
Looking ahead, we can expect the boundary lines between backup/recovery and threat detection to continue dissolving. Future iterations of these technologies will likely incorporate even deeper predictive analytics, autonomous threat-hunting loops, and cross-platform orchestration that extends beyond Active Directory into multi-cloud SaaS identity environments. For enterprise security leaders, this evolution offers a promising path forward: a resilient, self-healing identity infrastructure capable of neutralizing advanced threats at machine speed.
