Commvault has announced a new integration with CrowdStrike that adds Commvault cyber recovery actions as native steps within CrowdStrike’s Charlotte Agentic SOAR workflows.
The companies said the integration is intended to let joint customers automate recovery actions as part of security orchestration, with the goal of speeding incident response and forensic investigations and reducing manual coordination between security and recovery teams.
Commvault said the connector allows security teams to trigger actions including restricting access in Commvault during an incident, suspending backup data aging policies to retain recovery points, and restoring potentially compromised assets into Commvault Cleanroom for analysis without affecting production systems.
“Security and recovery teams need to move quickly and in coordination during an incident,” said Vidya Shankaran, Field CTO, Commvault. “Our integration with CrowdStrike Charlotte Agentic SOAR makes Commvault cyber recovery actions available directly within security workflows, helping joint customers reduce manual handoffs and accelerate investigation and response. This strengthens cyber resilience and simplifies how security and recovery teams work together seamlessly.”
Commvault said the announcement follows earlier integrations with CrowdStrike, including bringing CrowdStrike threat intelligence into Commvault Cloud via Falcon Insight XDR and extending visibility through Falcon Next-Gen SIEM.
The integration is generally available for joint Commvault and CrowdStrike customers and is also listed on the CrowdStrike Marketplace, according to the companies.

