ChannelLife New Zealand - Industry insider news for technology resellers
New Zealand
Rubrik & CrowdStrike launch faster identity attack fix

Rubrik & CrowdStrike launch faster identity attack fix

Thu, 3rd Sep 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Rubrik and CrowdStrike have introduced an integrated workflow for responding to identity-based cyber attacks, designed to cut recovery times from days to hours.

The integration combines CrowdStrike's Charlotte Agentic SOAR and Falcon Next-Gen Identity Security with Rubrik Identity Resilience in a single process spanning detection, investigation and recovery.

Identity attacks are a growing concern for security and IT teams because they can give intruders access to core systems, directories and applications. The new workflow is intended to reduce manual steps during a breach by linking threat detection with restoration of affected identity systems.

Under the arrangement, CrowdStrike handles detection and containment of malicious activity, while Rubrik uses that information with identity activity logs to help identify what changed and what must be restored. The process can be used to reverse unauthorised changes in Active Directory, remove malicious files and launch forest recovery plans.

Attack response

The announcement centres on what the companies describe as a closed-loop response model. In practice, this means the same workflow can move from alerting and investigation to remediation and recovery without the hand-offs that often slow incident response teams.

Another aim is to reduce the need for staff to switch between multiple security and IT tools during an incident. This could help security operations and infrastructure teams work within a more unified process when identity providers or directory environments have been compromised.

Daniel Bernard, Chief Business Officer, CrowdStrike, said the move extends an existing relationship between the two companies.

"Our long-standing partnership with Rubrik has always been about giving joint customers the best of both worlds. Today we execute on the next phase," Bernard said.

"By bringing CrowdStrike and Rubrik together via agentic workflows, we're empowering organisations to contain and recover from identity-based attacks faster than ever," he said.

Identity pressure

The companies framed the launch against rising concern over attacks targeting identity systems. Rubrik cited research from its Zero Labs unit showing that 90 per cent of IT and security leaders viewed identity-based attacks as the single largest threat to their organisations.

That concern reflects the central role of identity infrastructure in modern corporate networks. If attackers gain access to identity systems, they can often move laterally, maintain persistence and interfere with recovery efforts, making the speed and reliability of restoration a major issue after an intrusion.

Rubrik said the integrated workflow can also analyse context from Human Resources Information Systems and identity governance and administration platforms across backup data. The aim is to help teams trace suspicious changes and determine whether identity records or permissions were altered as part of an attack.

Anneka Gupta, Chief Product Officer, Rubrik, linked the company's position to the growing use of artificial intelligence by attackers and the shrinking window for human intervention.

"As adversaries weaponise AI and a breach unfolds in milliseconds, relying on human reaction time is risky and obsolete," Gupta said.

"We integrated Rubrik and CrowdStrike because you can't fight rapid AI threats with manual workflows. You need automated, intelligent defence to shut down active attacks instantly and guarantee a clean, fast recovery," she said.

Existing links

The latest integration builds on other identity-focused links already supported between the two companies' products. According to Rubrik, these include Falcon Next-Gen SIEM, Charlotte Agentic SOAR, Falcon Next-Gen Identity Security and Threat Intelligence.

For customers, the pitch is not only faster containment but a cleaner return to service. In identity incidents, restoring operations without removing attacker persistence can leave organisations exposed to repeat compromise, particularly if directory changes or privileged accounts have been tampered with.

The workflow is designed to close an incident with minimal manual intervention once detection, correlation and recovery actions are completed. A key measure highlighted by the companies is reducing recovery time objectives for identity providers from days to hours.

That claim places the focus as much on recovery as on prevention, an area that has drawn more attention as companies face pressure to restore critical systems quickly after breaches while proving restored environments are free of malicious changes.

The process described by the two vendors centres on identity environments rather than broader endpoint or network recovery, reflecting the view that access controls and directory services have become one of the most sensitive layers in enterprise security.

Rubrik said teams can use the workflow to recover identity providers to clean, current states.