ghunt/sh
Live · Real-time Google lookups

Run GHunt online.Every Google trace from one email.

ghunt.sh is the no-install way to run GHunt, the Google account OSINT framework, right in your browser. Drop an email and every public footprint it leaves comes back in one consolidated report.

    What is GHunt?

    GHunt, short for Google Hunt

    GHunt is an open-source OSINT framework that turns a single Google identifier into a clear picture of an account's public side. Give it an email and it resolves the Gaia ID behind the address, then follows that ID across Google's own public services to build one consolidated dossier.

    Nothing private is ever touched. GHunt reads only what the owner has already chosen to expose through Google's settings, with no password attacks, no MFA bypass and no scraping of locked content. ghunt.sh brings that exact workflow to the browser, so you skip the Python setup, the Companion extension and the token juggling the original tool needs.

    Read the full GHunt explainer

    Every public Google surface, one consolidated report.

    Whatever the target has chosen to expose, stitched into one report.

    1. SOURCE / 01

      Public Google profile

    2. SOURCE / 02

      Google Maps contributions

    3. SOURCE / 03

      Public Google Calendar

    4. SOURCE / 04

      Play Games profile

    5. SOURCE / 05

      Pivot identifiers

    $ only data the account owner has chosen to make public. No passwords, no scraping of private content.

    Everything GHunt pulls from one email

    Six capabilities in one console, instead of juggling half a dozen scripts.

    • Google account lookup

      Turn an email into a public Google profile: display name, photo, cover image, account language, and whether it is a personal Gmail or a Workspace seat.

    • Gmail & email investigation

      Confirm whether an address is wired to a live Google account and which Google services it actively uses, the quick way to qualify a target before a deeper dig.

    • Maps-based geolocation

      Read the GPS coordinates carried by public Maps reviews and photos to estimate a probable home or activity area, with a confidence score and travel outliers kept separate.

    • Privacy exposure audit

      See an account the way a stranger does. Run your own address and find exactly which reviews, photos, events and identifiers Google is quietly showing the public.

    • Consolidated report & export

      Every surface lands in one structured report you can read, share through a private link, or export as a self-contained archive for your case file.

    • Identity pivoting

      Copy the Gaia ID and chain it across Maps, Play Games and Drive, or jump from a shared file straight to its owner. One starting point, many threads to pull.

    From identifier to dossier in three steps.

    Nothing to install, no setup. Drop something Google has ever indexed and pivot from what comes back.

    1. STEP / 01

      Drop an identifier

      input

      Paste an email, a Gaia ID, a Drive link, a BSSID, or a domain. The console picks the right module automatically.

    2. STEP / 02

      Cross-reference services

      process

      ghunt/sh asks the right Google service for each identifier and stitches the responses into one consolidated report.

    3. STEP / 03

      Pivot from the result

      output

      Every result is broken down into clear sections. Copy a Gaia ID, jump from a file owner to their email, keep digging.

    GHunt by the numbers

    What the online version actually delivers, no marketing math.

    5
    public Google surfaces
    Profile, Maps, Calendar, Play Games, pivot IDs
    0
    things to install
    No Python, no extension, no tokens
    100%
    public data only
    No password attacks, nothing private scraped
    Seconds
    from email to report
    Results stream in as they are found

    Built for people who already know what they're looking for.

    Different goals, one primitive: a Google identifier in, an enriched public dossier out. Six kinds of people keep coming back to it.

    • 01

      Red teams & pentesters

      Map the attack surface around a phished employee in seconds. Find their Workspace domain, the apps they actively use, then pivot to lateral targets.

      • Identify the Workspace tenant
      • Spot personal vs. corporate accounts
      • Pre-engagement OSINT
    • 02

      Threat intel analysts

      Resolve a Gmail address that surfaced in a leak: profile photo for face matching, Maps reviews for routine, Calendar for upcoming events.

      • Leak triage
      • Actor attribution
      • Cross-source enrichment
    • 03

      Journalists & researchers

      Verify the public footprint of a source or subject: names they sign reviews under, places they've geotagged, public events they own.

      • Source verification
      • Story corroboration
      • Open-source forensics
    • 04

      Digital forensics & DFIR

      Corroborate an identity early in a case using public-only signals: tie an email to a named profile, anchor it on a map through Maps activity, line it up against public events.

      • Identity corroboration
      • Non-intrusive triage
      • Timeline building
    • 05

      Privacy & personal security

      Audit your own footprint before anyone else does. See which reviews, photos, events and identifiers are public, then tighten the settings leaking the most.

      • Self-audit
      • Exposure check
      • Footprint cleanup
    • 06

      Awareness & training

      Show a team, in one consented live demo, how much a single email reveals. A concrete example lands harder than another slide about oversharing.

      • Awareness demos
      • Social-engineering prep
      • Consented examples

    GHunt online vs the Python CLI

    Same lookups, two very different experiences. The browser version strips out everything that usually goes wrong.

    GHunt CLI (Python)
    ghunt.sh (online)
    Setup
    Python 3.10+, virtualenv, pip, Companion extension
    Open a page, paste an email
    Skill needed
    Comfortable in a terminal
    None
    Authentication
    Your own Google session, captured by hand
    Handled for you
    Output
    Raw JSON in the terminal
    Visual report, share link, export
    Upkeep
    Breaks when Google shifts; you patch and wait
    Maintained for you

    Either way, GHunt only reads public data and never bypasses MFA or recovers passwords.

    See the full web vs CLI breakdown

    Why ghunt/sh

    A single console for the kind of OSINT that usually requires juggling half a dozen scripts.

    Multi-source pivots
    A single email surfaces Maps reviews, Calendar events, Play Games activity, profile photos and more. Pivot between identifiers without leaving the console.
    Public data only
    Every query targets data the account owner has chosen to make public. No password attacks, no scraping of private content.
    Free to search
    Searches are free and run in real time. Unlock the full report for a credit when you need the complete picture.
    For authorized use
    Pentests, threat-intel investigations, journalism. Reading these results implies you accept the responsibility that goes with them.

    What practitioners say

    How investigators describe working with GHunt online.

    • Paste an email, get a clean report in seconds. It is the first thing I run before deciding whether a lead is worth a deeper local dig.

      Red team operator

    • The Gaia ID pivot alone saves me an afternoon of cross-checking Maps and Play Games by hand.

      Threat intelligence analyst

    • I ran my own address and was surprised how much was public. A great way to show a newsroom why this matters.

      Investigative journalist

    Composite feedback that reflects how people describe the tool. Swap in your own verified quotes anytime.

    Frequently asked questions

    What the OSINT community asks most often before paying attention.