Event Investigation

Back to Security Events
HIGHConfidence: 89%
Rule: RULE-NET-201Incident: INC-2026-0816

Suspicious Redirect Chain

What BOSS Detected

Service worker intercepted multi-hop HTTP redirects spanning 4 cross-origin boundaries.

Observed Evidence

Destination URL:https://gateway.auth-redirect.io/oauth2/callback
Content Type:text/html
Payload Size:4.1 KB
Redirect Hops:4
Matched Indicators:
Multi-origin redirect chainQuery parameter token reflection

Correlated Detection Signals

Cross-origin redirect cascade
91%
Potential token exposure risk
87%

Event Sequence Timeline

12:45:00
Initial redirect response received (302 Found)
12:45:01
Follow-up redirect 2 -> 3 -> 4 tracked
12:45:02
Reported to Rocket backend telemetry service
{
  "event_type": "REDIRECT_CHAIN_ANOMALY",
  "redirect_hops": [
    "auth.example.com",
    "track.ad-net.com",
    "proxy.relay-sec.org",
    "gateway.auth-redirect.io"
  ]
}