Skip to main content

Netskope Joins CrowdStrike Project QuiltWorks and Adds 3 Integrations

2 companies named across 4 categories, one of 283 articles referencing Netskope. Previous coverage: Modern Retail: Secure, Connected, and AI-Ready (Sep 2026).

Companies mentioned

Best suited for

Seniority
EVP / SVP / VP / AVP
Job function
Cybersecurity / Security Operations
Persona
Security Operations Leader
Buyer role
Decision Maker / Budget Holder
Buyer journey
Need to Buy
Adoption curve
Early Majority
Technology maturity
Operational Expansion
Industry
Information Technology / Software & Services / Cybersecurity / SIEM & Security Analytics

Our classification, not the publisher's statement. Best suited for, not only for.

CrowdStrike expanded Project QuiltWorks to incorporate near real-time Netskope telemetry, and the companies introduced three new integrations that connect Netskope events to automated detection and response in the Falcon platform.

Research Overview

The vendor update centers on Project QuiltWorks, an initiative that unites vulnerability discovery with security ecosystem data. CrowdStrike says it expanded the program to include Netskope telemetry to provide additional context for prioritization and action.

The post also describes new bidirectional integration flows between Netskope and CrowdStrike Falcon, where telemetry and risk signals move across both products. It frames these changes as more automated correlation and enforcement actions across the platforms.

Key Findings

Project QuiltWorks now includes Netskope telemetry, described as real-time in the Falcon environment. The update also states that Netskope publishes three new CrowdStrike integrations for automated detection and response.

The integrations are described as enabling signal flow in both directions, with Netskope telemetry reaching CrowdStrike and CrowdStrike risk scores reaching Netskope. The post describes an event-to-detection-and-response path as well as a risk-score-to-policy-response path.

Technical Breakdown

For the direction from Netskope to CrowdStrike, the post says Netskope AI SecOps events are streamed to Falcon Next-Gen SIEM via an outbound webhook in near real time. It also states that a netskope-sse parser normalizes 16 event types into a consistent set of fields at ingest.

One described integration uses a Falcon Next-Gen SIEM correlation rule to turn a qualifying Netskope event into a Falcon detection. The workflow then incorporates an existing CrowdStrike AI agent for endpoint and identity context and uses a Charlotte Agentic SOAR workflow to apply a verdict such as tagging a device, adjusting a Netskope User Confidence Index recommendation, or restricting access.

For the direction from CrowdStrike to Netskope, the post describes an integration in which a Charlotte Agentic SOAR workflow monitors changes to a host’s Falcon Zero Trust Assessment score. It states the workflow resolves the matching device on the Netskope side and calls the Netskope Device Tags API to apply one of three risk tags.

It further states that each risk tag maps to a Netskope Device Classification rule and a Real-Time Protection policy, shifting enforcement posture as the score changes. The post says this approach does not require a Cloud Exchange plugin.

Operational Impact

The post describes the combined effect as allowing a Netskope event to trigger a CrowdStrike detection and response while a CrowdStrike risk score triggers a Netskope policy change. It emphasizes that these actions occur without manually copying data between consoles.

It also includes implementation detail around workflow testing, stating that a human sets the confidence threshold and runs the workflow in a sandbox tenant before actions affect production devices. The post characterizes the operational goal as reducing manual triage by coupling correlated signals with automated workflows.

“AI, cloud, and SaaS adoption have permanently transformed how users interact with data, and today our customers are rearchitecting security and networking for a world where both human and non-human identities need secure access to data and applications. As part of the longstanding and highly productive CrowdStrike and Netskope partnership, Netskope telemetry will now provide Project QuiltWorks with critical insight across users, AI, applications, and data, helping defenders identify connected risks and prioritize fast action.”

Blog post, originally published by Kevin Cornejo at netskope.com.