In June 2026 researchers uncovered FortiBleed, a campaign that harvested more than 86,000 valid credentials from Fortinet firewalls and VPNs across 194 countries. Roughly half of the exposed devices still had working credentials attached. The attackers did not need malware or a foothold; they simply logged in and moved through networks looking like legitimate users making routine changes.
There was nothing for endpoint protection tools to catch: no exploit, no payload, no anomaly signature—just a seemingly valid login.
AI-powered attacks are accelerating this pattern at a lightning pace. Once an adversary holds a valid credential, AI makes escalating privileges and moving laterally across systems faster and easier, often with little or no human intervention. According to CrowdStrike's 2026 Global Threat Report, AI-enabled cyber incidents rose 89% year over year.
Enterprises built their detection and response playbooks for a world where humans attacked at human speed. That world is gone.
To detect and recover before an AI-accelerated attacker finishes the job, security and IAM teams need every relevant signal and every piece of identity context. The Identity Intelligence Fabric, part of Rubrik Identity Resilience, gathers signals from the security and identity tools an enterprise runs and aggregates identity context in a single, integrated layer. This helps teams detect, investigate, and recover from AI-driven attacks at machine speed.
The Fragmentation Problem
The average enterprise runs about 61 security tools and 58 dashboards, according to Panaseer's 2026 Security Leaders Peer Report, and Gartner expects security spending to keep growing at roughly 10% a year.
More tools were supposed to mean more security. Instead, they produced more silos.
First, consider detection. When a signal fires in one tool, confirming it means manually correlating alerts across EDR platforms, SIEM, and identity systems, followed by pulling multiple teams into a war room to reconstruct the incident. Piecing together a picture of the incident is difficult without an immutable, indelible activity log. Rubrik solves this with a tamper-resistent activity log with actor attribution, helping teams map the blast radius.
Next, consider the response. Once an attack is confirmed, reconciling the changes between the last known clean state and the present requires identity context that lives across the entire enterprise stack: workforce data in HR systems like Workday, access data in an IGA tool, native object data in identity providers like Entra ID and Okta, and privileged access data somewhere else entirely. When that context is scattered, reconciliation becomes a manual, cross-tool investigation. It takes days, and the business stays down.
Today Rubrik introduces two sets of integrations that begin to close the gap between detection and response.
Faster Detection with CrowdStrike and Microsoft Defender
Rubrik Identity Resilience ingests alerts from CrowdStrike and Microsoft Defender and correlates them against enterprise identity snapshot data. When a critical identity attack signal appears (such as a Golden Ticket, DCSync, or Golden SAML) that signal becomes a single decisive trigger for IAM admins to loop in security teams.
This does not replace the analyst's job of piecing together alerts across the security and identity systems to understand whether a domain is compromised, what changed, and how severe the incident is. Instead, by bringing security and IAM teams to the same signal at the same time, Rubrik gives both teams the confidence to know when and where to begin recovery, closing the gap between detection and response.
Quick Reconciliation with Workday and SailPoint
Detection tells you when an attack happens. Reconciliation tells you which changes are legitimate, which are malicious, which to undo, and which to keep.
Rubrik recently introduced Identity First Recovery (IFR), a way to simplify Active Directory Forest Recovery (ADFR) and help organizations through the recovery process. One of Rubrik’s biggest value propositions, in addition to a full ADFR, is surgical rollback in which Rubrik can undo unwanted changes without needing a full forest recovery. Teams can undo unwanted changes directly from the immutable, tamper-resistent activity log.
These new integrations with the Identity Intelligence Fabric significantly enhance the surgical rollback process with context across the enterprise identity stack, including context from HR systems like Workday and IGA systems like SailPoint. Rubrik can now quickly separate malicious changes from legitimate changes through a unified console, protecting IAM teams from expending the time and effort required to manually reconcile context across systems by hand. Ultimately, this reduces incident response time.
Where the Identity Intelligence Fabric Goes Next
These integrations are just the start. Rubrik plans to expand significantly, connecting to more ITDR platforms and identity systems of record, including additional HR, IGA, PAM, and ITSM platforms. The goal is for Rubrik to become the single place where security and IAM teams detect an attack, investigate it, and begin recovery, all from the same console.
Ready to See it in Action?
An AI-accelerated attacker does not wait for enterprises to finish correlating alerts across multiple tools. The Identity Intelligence Fabric is how Rubrik gives enterprises the context to respond at machine speed and recover with confidence.
Schedule a demo to see how Rubrik unifies signals from your existing security stack to detect, reconcile, and recover from identity attacks at machine speed, or visit rubrik.com/identity to learn more.
SAFE HARBOR
Any unreleased services or features referenced on this page are not currently available and may not be made generally available on time or at all, as may be determined in our sole discretion. Any such referenced services or features do not represent promises to deliver, commitments, or obligations of Rubrik, Inc. and may not be incorporated into any contract. Customers should make their purchase decisions based upon services and features that are currently generally available.
NOTE
Please speak to Rubrik representatives to confirm the availability and functionality of Rubrik's products and services before making any purchase or renewal decisions.