Commvault has integrated its cyber-recovery actions directly into CrowdStrike Charlotte Agentic SOAR, allowing customers of both companies to incorporate backup and recovery-environment tasks into their automated security workflows. The integration is available now and aims to close one of the recurring gaps during an attack: the separation between the teams investigating and containing the threat and the teams responsible for protecting and recovering the data.
Commvault and CrowdStrike in 20 seconds
- Commvault adds cyber-recovery actions as native steps inside Charlotte Agentic SOAR.
- Teams can restrict access and preserve recovery points during an active incident.
- Suspicious assets can be restored in Commvault Cleanroom for analysis outside of production.
- The integration is available to joint customers and extends the two companies’ existing collaboration.
The move is especially relevant for ransomware attacks and other intrusions where the response doesn’t end once a compromised machine has been isolated. Before starting recovery, teams need to determine how far the attacker got, which backups can still be trusted, and which systems can be restored without reintroducing the threat.
That’s where two areas that have traditionally relied on different tools and procedures come together: SecOps, which handles security operations, and the teams responsible for backup and recovery.
Commvault and CrowdStrike want part of that work to be coordinated from the same response workflow.
From the security alert to immediately protecting the backups
SOAR stands for Security Orchestration, Automation and Response, a category of tools designed to coordinate and automate the actions that follow the detection of a threat.
Charlotte Agentic SOAR is part of the CrowdStrike platform and uses AI-driven automation to investigate alerts, make decisions within established policies, and carry out actions across different systems.
The integration unveiled on August 31 adds Commvault-specific actions to those procedures.
One of them lets teams restrict access to Commvault during an active incident.
The measure serves a specific purpose. If an attacker still holds privileged credentials or access to certain systems, they may try to modify or delete the backups that will later be needed to recover the infrastructure.
The security workflow can now include access restriction as one of the measures taken right after an incident is detected, rather than depending on a separate intervention from the backup team.
Another action affects retention policies.
Backup systems normally delete old data according to each organization’s configured policies. That’s a necessary process for managing available capacity, but during an investigation it can cause a recovery point that later turns out to be useful to disappear.
Commvault lets Charlotte Agentic SOAR automatically suspend backup data aging policies during an incident.
That doesn’t mean every backup that’s preserved automatically becomes safe. Its usefulness still has to be determined during the investigation. The feature simply prevents certain recovery points from disappearing while teams try to reconstruct what happened and since when the environment was compromised.
Restoring a suspicious server without putting it back into production
The third feature connects the investigation with Commvault Cleanroom Recovery.
Instead of restoring a potentially compromised asset directly onto production infrastructure, the system can move it into an isolated environment.
Investigators then have a copy they can use to analyze files, configurations, and other elements related to the incident without interfering with the systems that are still in service.
That separation matters because recovering data and safely recovering a service are two different problems.
A backup may have completed successfully and contain all the expected data, yet still date from a moment when the attacker was already present.
It may also include malware, persistence mechanisms, modified configurations, or compromised credentials.
Restoring it directly can bring the system back to a working state while, at the same time, reintroducing part of the compromise that caused the incident in the first place.
Isolated environments make it possible to add an intermediate stage between backup and production: restore, inspect, validate, and only then decide what can go back.
The new integration allows that procedure to be folded into the workflow started from Charlotte Agentic SOAR.
Automation connects two different moments of the attack
The practical value of the integration isn’t just about automatically triggering a restore.
The full sequence is more interesting than that.
A detection platform can identify suspicious activity, launch an investigation, and contain certain systems. From that point on, it may also become necessary to immediately protect the recovery infrastructure.
Before this integration, those tasks could require manual notifications between teams, access to different consoles, and separate procedures.
Commvault wants to turn some of that into actions available directly from CrowdStrike’s security workflow.
That can be especially useful when every minute counts.
An attacker who has gained elevated privileges may go after the backups precisely because they know those are the organization’s last option for avoiding a ransom payment or rebuilding systems from scratch.
Automating protection of those resources reduces the time between detecting a threat and taking the first steps to secure the recovery environment.
That doesn’t eliminate human involvement or turn full recovery into an autonomous process.
Deciding which data can be trusted, when to restore it, and when to reconnect a system to production still requires controls, policies, and validations tailored to each organization.
CrowdStrike and Commvault were already sharing security information
The relationship between the two platforms didn’t start with Charlotte Agentic SOAR.
Commvault had already integrated CrowdStrike Falcon Insight XDR to bring information from CrowdStrike into Commvault Cloud.
It later added an integration with Falcon Next-Gen SIEM, aimed at extending visibility into events related to the protected environments.
The new connection completes another part of that journey.
The earlier integrations were about sharing signals and information. Now Commvault’s recovery actions can be built directly into automated response procedures.
The change also reflects a broader shift in enterprise cybersecurity.
For years, backup was seen mainly as a tool for fixing failures, human errors, or infrastructure problems. Ransomware turned it into a security tool as well.
A recovery strategy against an attack needs to know not just whether a backup exists, but when it was created, whether it can be considered clean, whether the attacker could have tampered with it, and how to restore it without compromising the environment again.
That’s why detection systems and recovery platforms are increasingly exchanging information with each other.
Agentic AI enters both response and recovery
Charlotte Agentic SOAR adds another dimension too: the growing use of AI agents within security operations.
The promise of these platforms is to cut the manual work needed to investigate signals, correlate information, and carry out previously defined procedures.
But the speed of an automated investigation doesn’t count for much if, once it’s time to protect the backups or start a recovery, the process goes back to depending on manual communication between departments.
Commvault’s integration tries to extend that automation into the recovery phase.
It’s worth separating automation from full autonomy, though.
The ability to run actions on backups from a SOAR workflow demands especially strict controls. A misfired automation on recovery infrastructure can have serious consequences, precisely because that data is the last line of defense once production has been compromised.
The policies, permissions, and limits each organization sets remain, therefore, an essential part of the design.
Commvault presents the integration as a way to cut manual handoffs between security and recovery teams, not as a replacement for either one.
That distinction matters.
The goal is that when CrowdStrike detects and manages an incident, the procedure can immediately extend to the systems that will be needed if the infrastructure ultimately has to be recovered.
Detecting sooner doesn’t help much if recovery still takes days
Enterprise cybersecurity has spent a great deal of resources on shortening mean detection and response times.
But a serious incident can leave systems encrypted, deleted, or deliberately altered even after the attacker has already been kicked out.
That’s when another metric comes into play: how long it actually takes the company to get its operations back.
A good detection system can spot ransomware quickly and still leave the organization without certain services for several days if the recovery process is slow, backups have to be verified manually, or it’s unclear which point in time is safe.
The convergence between CrowdStrike and Commvault tries to bring those two phases closer together.
The security platform supplies information about the incident and organizes the response. The data protection platform holds the backups and provides the mechanisms to restore them. The new connector lets some of the decisions between those two worlds become part of the same procedure.
The integration is generally available to joint Commvault and CrowdStrike customers and is also distributed through the CrowdStrike Marketplace.
It doesn’t automatically make an infrastructure ransomware-proof, nor does it guarantee that a restore will come back clean. Protected backups, isolation, regular testing, identity controls, and recovery plans are all still necessary for that.
What it does reduce is a gap that can prove costly during an emergency: the operational distance between detecting that something is happening and starting to protect the data that will make it possible to get back up and running.
Frequently Asked Questions
What have Commvault and CrowdStrike integrated?
Commvault has added cyber-recovery actions as steps available within CrowdStrike Charlotte Agentic SOAR workflows. This allows certain protection and recovery tasks to be coordinated from within the security response procedures.
What can Charlotte Agentic SOAR do with Commvault?
The integration can restrict access to Commvault, suspend data-aging policies to preserve recovery points, and restore potentially compromised assets inside Commvault Cleanroom for analysis.
What is Commvault Cleanroom for?
It restores systems into an isolated environment where they can be investigated and validated before being considered for a return to production. The goal is to prevent a recovery from reintroducing elements tied to the attack.
Is the integration available yet?
Yes. Commvault says the integration is generally available to joint Commvault and CrowdStrike customers and can also be found on the CrowdStrike Marketplace.

