Research Finder
Find by Keyword
VAST and CrowdStrike Bring Falcon Inside the AI Data Platform
Certified native Falcon sensor support extends CrowdStrike protection directly onto VAST AI OS, while new SIEM and InsightEngine integrations connect AI data infrastructure with the broader Falcon security architecture.
9/03/2026
Key Highlights
- VAST AI OS now supports the certified CrowdStrike Falcon sensor natively, extending Falcon protection directly onto infrastructure serving enterprise AI workloads.
- VAST audit telemetry will integrate with Falcon Next-Gen SIEM to add data-access context to endpoint, identity, and other cyber telemetry. The capability is in private preview.
- Falcon Guardian will integrate with VAST InsightEngine using the NVIDIA AI Data Platform reference design to identify and classify sensitive information as data enters AI knowledge bases. The integration is in private preview.
- CrowdStrike already supports a broad storage and cyber-resilience ecosystem. VAST runs Falcon on the AI data platform and connects data-layer telemetry and AI workflows into the broader Falcon environment.
- The announcement follows the companies’ February 2026 architecture for coordinated AI security, with native Falcon support now available and deeper correlation and response capabilities still progressing toward delivery.
The News
VAST Data and CrowdStrike have expanded their partnership with integrations spanning AI infrastructure, data-access telemetry, and AI security. VAST AI OS now supports the certified CrowdStrike Falcon sensor natively, while integrations with Falcon Next-Gen SIEM and Falcon Guardian are in private preview. Falcon Guardian will integrate with VAST InsightEngine using the NVIDIA AI Data Platform reference design. For more information, refer to the official VAST press announcement.
Analyst Take
Enterprise AI creates more machine-driven access to corporate information as applications, models, and agents work alongside human users. Security teams need visibility into activity at the data layer and the ability to correlate that activity with identities, endpoints, workloads, and AI runtime behavior. CrowdStrike already extends Falcon into storage and cyber resilience through vendors including Rubrik, Cohesity, Commvault, Veeam, and Nasuni. Those integrations give enterprises multiple ways to combine storage, backup, threat, and recovery information with Falcon while maintaining infrastructure choice.
VAST runs the Falcon sensor directly on VAST AI OS, bringing the data platform inside CrowdStrike’s protected estate. This aligns with CrowdStrike’s Guardian architecture, which uses the Falcon sensor as the control point for AI agent activity and extends protection from endpoints into cloud, SaaS, browser, and infrastructure environments. Running Falcon directly on VAST could provide richer security context than telemetry alone because the sensor can participate in detection and enforcement on the infrastructure where enterprise data is served and processed.
InsightEngine will use Guardian to help identify and classify sensitive information such as PII as data enters AI knowledge bases. Guardian then applies AI-specific threat detection, including prompt injection and jailbreak attempts, as users, agents, and applications interact with AI systems through CrowdStrike’s endpoint-anchored sensor architecture. That combination becomes more relevant with agentic AI. An investigation may need to trace an identity to an agent, the agent to a dataset, that dataset into model context, and the resulting activity into another system. VAST contributes data-layer context while CrowdStrike correlates it with security signals elsewhere in the enterprise.
HyperFRAME Lens: State of the Enterprise Infrastructure and Operations (1H 2026) research based on a survey of 520 enterprise decision-makers, found that 62% rate data security and governance as a critical priority, while 72% cite security as the leading barrier to scaling infrastructure. Bringing Falcon directly onto the AI data platform addresses that concern where sensitive information is stored, processed, and prepared for AI.
The broader CrowdStrike ecosystem keeps that model open. An enterprise can use VAST for AI data infrastructure while retaining other storage and cyber-resilience platforms elsewhere. Falcon provides a common security layer among those systems, while VAST adds deeper integration where AI data is stored, processed, and prepared.
The timing provides an execution benchmark. VAST and CrowdStrike described coordinated protection, automated response, data-layer governance, and platform-level controls in February. Six months later, native Falcon support is available and the SIEM and Guardian integrations have entered private preview. Visibility and correlation are beginning to ship, while the coordinated response capabilities described in February remain part of the architecture still to be delivered.
Guardian itself is also new, introduced at Fal.Con 2026 alongside the VAST announcement. The maturity of both Guardian and the VAST integration will therefore develop in parallel. In our view, the next proof point is whether shared visibility progresses into actions that can contain a threat on VAST or elsewhere in the Falcon environment.
What Was Announced
VAST and CrowdStrike describe the combined architecture as first-of-its-kind across an AI operating system. Native Falcon support is available today, while the Next-Gen SIEM and Falcon Guardian integrations are in private preview.
VAST audit telemetry will give security teams data-access context alongside endpoint, identity, workload, and other enterprise security signals. Guardian will extend that coverage into InsightEngine using the NVIDIA AI Data Platform reference design, helping identify and classify sensitive information such as PII as enterprise data is prepared for AI knowledge bases.
Guardian applies AI-specific threat detection, including prompt injection and jailbreak attempts, as users, agents, and applications interact with AI systems. CrowdStrike delivers those capabilities through its Falcon sensor architecture, anchored at the endpoint. VAST contributes classification and inspection of enterprise data as InsightEngine prepares it.
The companies also plan to demonstrate the integrations within an NVIDIA-powered AI factory using a VAST data pipeline supporting accelerated AI workloads. This places the VAST-CrowdStrike work inside an NVIDIA reference architecture used to assemble production AI infrastructure. From the VAST perspective, the architecture connects Falcon directly to AI OS infrastructure, exposes data-access activity to enterprise security operations, and brings sensitive-data classification into InsightEngine as enterprise information moves toward AI use.
Looking Ahead
Enterprises can now place VAST AI infrastructure inside the same Falcon protection model already used for other workloads and endpoints. That gives security teams direct sensor coverage on infrastructure storing and processing high-value AI data, alongside the data-access telemetry VAST can provide to Falcon Next-Gen SIEM. Security investigations can gain additional context when activity against sensitive information is correlated with identities, endpoints, workloads, and other Falcon signals. A suspicious access event on VAST can become part of the same incident trail used to investigate activity elsewhere in the enterprise.
The InsightEngine integration can increase confidence in building AI knowledge bases from regulated or sensitive information. Organizations can identify and classify data as it enters those environments, while Guardian applies AI-specific runtime protection as agents, users, and applications interact with AI systems. That combination can support more distributed AI deployment. Enterprises can keep sensitive information closer to its source while bringing the underlying data infrastructure into the same detection and investigation architecture used by the security team.
In February, VAST and CrowdStrike described automated response alongside VAST data-layer governance and platform-level controls. With the Falcon sensor now running directly on VAST, CrowdStrike gains a direct enforcement point on the data platform itself. If future integrations allow Falcon detections to trigger actions such as restricting access, isolating affected workloads, or blocking compromised data from entering an AI workflow, security teams could contain threats closer to the information involved and reduce manual coordination between security and infrastructure teams while preserving choice elsewhere in the infrastructure estate.
Don Gentile | Analyst-in-Residence, Data Platforms & Resiliency
Don Gentile brings three decades of experience turning complex enterprise technologies into clear, differentiated narratives that drive competitive relevance and market leadership. He has helped shape iconic infrastructure platforms including IBM z16 and z17 mainframes, HPE ProLiant servers, and HPE GreenLake — guiding strategies that connect technology innovation with customer needs and fast-moving market dynamics.
His current focus spans flash storage, storage area networking, hyperconverged infrastructure (HCI), software-defined storage (SDS), hybrid cloud storage, Ceph/open source, cyber resiliency, and emerging models for integrating AI workloads across storage and compute. By applying deep knowledge of infrastructure technologies with proven skills in positioning, content strategy, and thought leadership, Don helps vendors sharpen their story, differentiate their offerings, and achieve stronger competitive standing across business, media, and technical audiences.



















