GHunt
Command-line tool that investigates a Google account from an email and returns the profile, public reviews, and linked services it can read.

- Categories
- Email OSINT
- Type
- CLI
- Price
- Free
- Setup
- Advanced setup
GHunt is an offensive Google framework. The repo is mxrch/GHunt. Given an email that is a Google account, it tries to pull the public pieces of that account: the profile, Maps reviews and photos, YouTube, and other Google services the current version can still read.
“Offensive” here means it is written for people who already know how Google’s frontends work. It does not mean the tool bypasses authentication in some magical way. You install it. You supply the credentials or cookies the current README asks for.
Google changes those frontends often, and GHunt is not kept current enough to match. Fixes sit in open pull requests. Getting a clean run usually means patching it yourself, not just following the install steps. That is why the setup label is advanced.
What you actually get
When it works, GHunt is one of the few free tools that can turn [email protected] into public Maps reviews and photos and a YouTube channel. That is often the first place a person is sloppy. Reviews have locations. Photos have locations. A channel has a join date and a real name.
When it does not, you are in cookie exports, a broken parser, and a morning of debugging. I still list it. I do not reach for it first.
When I use it
When I already know the address is a Google account and I need Maps or YouTube specifically. IntelBase and Behind the Email will surface some of the same Google signals on a paid plan, without the cookie dance. I still keep GHunt because it is local, it is inspectable, and it is the reference implementation for this niche.
Read the current repository before you install it. Instructions from a 2022 blog post will waste your day.



