Most attacks today move faster than a human analyst can read a dashboard. AI agents, non-human identities, and automated SaaS workflows now touch as much sensitive data as the people who deployed them, and each one adds another blind spot a security team has to awkwardly bend their neck to try to watch. Understanding risk is the first challenge, but it always needs to be completely integrated with efforts to mitigate it (before it becomes a breach).
Last week at Fal.Con 2026 in Las Vegas, we significantly extended our partnership and integrations with CrowdStrike to bring together insights and action, in order to address risk for customers. In fact, as well as announcing that we are part of CrowdStrike’s newly expanded Project QuiltWorks (an effort to unite ecosystem data behind faster, more automated defense), we also unveiled three new integrations that turn Netskope telemetry into automated detection and response inside the CrowdStrike Falcon® platform.
Here’s the TL;DR:
- CrowdStrike has expanded Project QuiltWorks to include near real-time Netskope telemetry.
- Netskope is publishing three new CrowdStrike integrations for automated detection and response.
Netskope joins CrowdStrike Project QuiltWorks
CrowdStrike has expanded Project QuiltWorks (its initiative to unite AI-driven vulnerability discovery with data from across the security ecosystem) to include real-time telemetry from Netskope. The premise is straightforward: The more context Falcon has about how users, AI agents, applications, and data actually behave, the faster a defender can prioritize what matters and act on it.
Andy Horwitz, SVP of Global Partner Ecosystems at Netskope, explained why that context matters now.
“AI, cloud, and SaaS adoption have permanently transformed how users interact with data, and today our customers are rearchitecting security and networking for a world where both human and non-human identities need secure access to data and applications. As part of the longstanding and highly productive CrowdStrike and Netskope partnership, Netskope telemetry will now provide Project QuiltWorks with critical insight across users, AI, applications, and data, helping defenders identify connected risks and prioritize fast action.”
That Netskope telemetry flows through CrowdStrike Falcon® Next-Gen SIEM’s real-time data pipelines, filtering and correlating data before it lands. From there, Falcon IQ layers in CrowdStrike threat intelligence and CrowdStrike Falcon® Adversary OverWatch™ findings, and pre-built CrowdStrike Charlotte AI™ agents handle onboarding and prioritization automatically. More data sources, correlated faster, means less manual triage for the security operations center (SOC).
Three new Netskope and CrowdStrike intelligence shares
Alongside the Project QuiltWorks news, three new integrations now connect Netskope and CrowdStrike Falcon even more directly, and the signal now runs in both directions: Netskope telemetry reaching CrowdStrike, and CrowdStrike risk scores reaching Netskope.
By layering these bi-directional capabilities onto our existing, proven integrations, we are extending our integration intelligence to provide deeper, automated risk mitigation across both platforms.
Netskope AI SecOps events > CrowdStrike Falcon Next-Gen SIEM. An outbound webhook streams Netskope cases, user risk, and AI risk events into Falcon Next-Gen SIEM in near real time. The netskope-sse parser automatically normalizes 16 event types into a consistent set of fields at ingest, so analysts get searchable, correlated data without building a parser first. (see the how-to)
Automated verdict and response in CrowdStrike. This builds on the integration above. A Falcon Next-Gen SIEM correlation rule turns a qualifying Netskope event into a Falcon detection, an existing CrowdStrike AI agent enriches it with endpoint and identity context, and a Charlotte Agentic SOAR workflow applies the resulting verdict, tagging a device, adjusting a Netskope User Confidence Index (UCI) recommendation, or restricting access, inside guardrails the customer sets first. (see the how-to)
We’ve seen plenty of partner integrations promise real-time response and quietly just move the same manual review to a different screen. This one genuinely speeds up the review. A human still sets the confidence threshold and runs the workflow in a sandbox tenant before anything touches a production device.
CrowdStrike Falcon Zero Trust Assessment > automatic Netskope policy response. This integration runs in the other direction to the previous two. A CrowdStrike Charlotte Agentic SOAR workflow watches for a host’s Falcon Zero Trust Assessment score to change, resolves the matching device on the Netskope side, and calls the Netskope Device Tags API to apply one of three risk tags. Each tag maps to its own Netskope Device Classification rule and Real-Time Protection policy, so a device’s enforcement posture shifts automatically as its score moves, in either direction, with no Cloud Exchange plugin required. (see the how-to)
Put together, a Netskope event can trigger a CrowdStrike detection and response, and a CrowdStrike risk score can trigger a Netskope policy change, without anyone copying data between consoles by hand.
Want to see the full picture of how our platforms unify your security? Explore the Netskope and CrowdStrike Joint Solution Brief.
Sources:
CrowdStrike Project QuiltWorks announcement, August 31, 2026