GHunt OSINT Review: Google Account Lookups, Login Risks and Limits

GHunt OSINT is an open-source command-line framework for investigating Google accounts: given a Gmail or Google-linked email address, it reports what Google exposes about the account behind it. It only works after you log it in with the session cookies of a Google account, which is the main risk this review explains.

  • Free, AGPL-3.0 license
  • Requires a logged-in Google session
  • Email, Gaia ID, Drive and BSSID modules
  • Version 2.3.4, March 2026

Based on the GitHub repository, its source code and PyPI release history, checked 10 October 2026. OSINT-S has no affiliation with the project.

Short answer

GHunt is a free AGPL-3.0 Python framework that looks up the Google account behind an email address or Gaia ID, returning items such as profile photos, last profile edit, active Google services and public Maps or Calendar data. It suits technical investigators and authorized red teams. It needs Google session cookies from an account you control, which brings account, security and terms-of-service risk.

What GHunt OSINT Does

GHunt queries Google services from a logged-in session to show what a Google account exposes publicly or semi-publicly, starting from an email, a Gaia ID or a Drive link.

The author describes GHunt (v2) as "an offensive Google framework", currently focused on OSINT (GHunt on GitHub). It runs as a command-line tool or as a Python library, is fully asynchronous and can export results as JSON. The repository is maintained by mxrch under the AGPL-3.0 license, requires Python 3.10 or newer, and its latest PyPI release, 2.3.4, was published on 16 March 2026 (PyPI).

Gmail addresses are common in fraud, harassment and impersonation cases, so GHunt fills a gap that general email tools cover only partly. It belongs to the email and identity section of our OSINT tools catalog, next to Holehe and Epieos.

GHunt Modules and the Data They Return

Five lookup modules plus login: email, gaia, drive, geolocate and spiderdal. The email module is the one most investigators use.

ModuleInputWhat it reports (per README and source)
emailEmail addressWhether a Google account matches; Gaia ID; custom profile and cover photos; last profile edit time; activated Google services; Play Games profile; Maps data; public Google Calendar
gaiaGaia ID (Google's internal account number)Account information from the ID rather than the email
driveDrive file or folder IDInformation on a shared Drive file or folder
geolocateBSSID (a Wi-Fi access point's hardware ID)An approximate location for that access point
spiderdalAndroid package, app certificate fingerprint or websiteRelated apps and sites declared through Digital Asset Links

Email module fields taken from the published email module source. What appears for a given account depends on that person's privacy settings and on how Google responds at the time.

A custom profile photo can be compared with images elsewhere, and public Maps reviews can show places a person has been. Each is a lead that needs independent confirmation.

Login, Cookies and Account Risk

GHunt needs the cookies of a logged-in Google account, supplied through its browser extension or pasted manually. Those cookies give full access to that account, and the activity is tied to it.

Before any lookup, GHunt has to be authenticated to Google. The README offers three login methods: a listening mode that receives cookies from the GHunt Companion browser extension (published for Firefox and Chrome), pasting base64-encoded cookies, or entering every cookie manually. All three hand the tool a live Google session.

  • Your account is exposed. Every lookup is made as the account you logged in with. Google's terms allow it to suspend or terminate access, or delete an account, after material or repeated breaches, and they prohibit "using automated means to access content from any of our services in violation of the machine-readable instructions" on its pages (Google Terms of Service, effective 30 July 2026). Never use a personal, work or administrator account.
  • Cookies are credentials. Session cookies let anyone who holds them act as that account. Storing them on a shared laptop, in a repository or in a ticket is a security incident waiting to happen.
  • The session leaves traces. The email module even reports whether the target is already in the logged-in account's contacts, which shows how closely the tool is tied to your own Google identity.

We describe these risks so buyers can judge them; this page deliberately gives no setup or command instructions.

GHunt License, Pricing and Maintenance

GHunt is free under AGPL-3.0 and actively released; a hosted online version is offered through OSINT Industries, a paid platform.

ItemStatus (checked 10 October 2026)
PriceFree; the author accepts GitHub sponsorship
LicenseAGPL-3.0, which requires sharing source code of modified versions offered to others over a network
LanguagePython 3.10+, compatible with 3.13 per the README
Latest release2.3.4 on PyPI, 16 March 2026
RepositoryPublic, not archived, about 19,500 stars
Hosted optionThe README links "GHunt Online version" to OSINT Industries, which sets its own prices

The README's disclaimer says the tool is for educational purposes and asks users to "use it only in personal, criminal investigations, pentesting, or open-source projects." Teams building GHunt into a commercial product should take legal advice on the AGPL first.

Who GHunt OSINT Suits and Who It Does Not

It suits technical investigators, threat researchers and authorized red teams who can isolate a dedicated account. It does not suit casual users or anyone without a lawful, documented purpose.

Good fit: fraud and threat analysts attributing a Gmail address used in a scam, and red teams mapping what an organization's Google accounts expose, within a signed scope. Our red team OSINT reconnaissance work always starts from written authorization.

Poor fit: anyone who cannot run Python safely, manage a separate Google identity and protect session cookies, and anyone who wants to look up a partner, an ex or a neighbor. A Google account is personal data about a real person, and curiosity is not a lawful purpose.

Limitations and Legal Risks of Google Account OSINT

Results depend on the target's privacy settings and on Google's changing responses, and every lookup is personal-data processing that needs a lawful basis.

  • Fragile by design. GHunt depends on how Google services answer requests. Changes on Google's side can break modules until a new release.
  • Partial picture. Many users keep reviews, calendars and photos private, so an empty result is common and proves nothing.
  • Attribution needs corroboration. A matching account shows who registered the address with Google, not who sent a particular email.
  • Data protection. Twelve data protection authorities stated in 2023 that publicly accessible personal information is still subject to data protection and privacy laws in most jurisdictions (joint statement on data scraping). Under the GDPR, document a lawful basis and keep only what the purpose needs.
  • No workarounds. Do not combine GHunt with leaked passwords, phishing or fake accounts to get more data. That moves from OSINT into unauthorized access.

GHunt Alternatives for Email and Google OSINT

Epieos runs a Google module in the browser without your cookies, Holehe checks wider site registration, and OSINT Industries hosts similar lookups commercially.

Web tool

Epieos

Includes a Google module on its free tier, run from the vendor's side, so no session of yours is involved.

Epieos review →
Open source

Holehe

Checks registration of an email across 120+ sites rather than depth on Google.

Holehe review →

Need the Answer, Not the Tool?

If you need to know who is behind a Gmail address for a legal, HR or fraud decision, an investigation delivers verified findings without putting your own Google account at risk.

Our email address investigations combine Google-account signals with headers, domains, usernames and public records, verify each link and grade it by confidence, with a senior analyst reviewing every report. If the question is what your own executives' Google accounts give away, a digital footprint assessment covers it. Focused cases start from 10 business days with a fixed quote after written scoping. See all OSINT services we provide to legal and security teams.

Behind a Gmail Address You Need to Explain?

Send the address and tell us what decision depends on it. We confirm the purpose and return a fixed quote and delivery date.

GHunt OSINT FAQ

I keep hearing about GHunt OSINT for Gmail addresses — what can it actually tell me about the Google account behind an email, and is it still updated?

GHunt OSINT can show whether an email matches a Google account and, depending on privacy settings, its Gaia ID, custom profile and cover photos, last profile edit time, active Google services, Play Games profile, public Maps data and public calendar. It is still updated: version 2.3.4 was published on PyPI on 16 March 2026, and the repository is not archived.

GHunt wants cookies from my Google account before it will run — could using it get my personal or company Google account suspended?

It could put that account at risk. GHunt runs every lookup as the account whose cookies you supply, and Google's terms allow suspension or termination after material or repeated breaches, including some kinds of automated access. Never use a personal, work or admin account, and treat the cookies as passwords. Many teams avoid the question by using a hosted tool or an investigation provider.

We're running an authorized red team engagement — is it appropriate to use GHunt to see what our client's staff Google accounts reveal?

It can be, if the scope letter covers OSINT on staff accounts and the client has a lawful basis for it under its own employment and privacy rules. Use a dedicated test identity, keep findings limited to what shows exposure risk, and report patterns rather than personal details where possible. Stay clear of password testing or phishing unless they are separately authorized.

Someone has been sending me threatening emails from a Gmail address — can I use GHunt to find out who they are and where they live?

Do not try to locate the sender yourself. Save the original emails with headers and report them to the police, who can request subscriber data from Google through legal process. GHunt might show a photo or reviews, but acting on that alone risks targeting the wrong person and escalating the danger. If a business is being targeted, an investigator can support the police report.

Is there a version of GHunt I can use online without installing Python and handing over my own Google cookies?

The GHunt README links an online version hosted by OSINT Industries, a commercial platform with its own subscription pricing. Epieos also runs a Google module in the browser, including on its free tier. Both avoid putting your own Google session into a local tool. Check each vendor's terms and data handling before you search a real person's address.

Our legal team needs to know who controls a Gmail address used to impersonate our CEO — should we try GHunt ourselves or hire an OSINT provider?

Hire a provider when the result will drive a takedown, a legal letter or a police report. GHunt gives leads; a provider verifies them against other sources, captures evidence with dates, explains confidence and keeps your accounts out of it. Impersonation cases often also need platform reporting, which is handled through brand protection work. Focused cases start from 10 business days.