All integrations
// Tentacle Tool · OSINT

Cracken + GHunt

Cracken runs GHunt to resolve an email address into the Gaia ID Google assigns the account behind it. It pivots on that ID for the public profile it exposes.

Get started
// 01

Connecting GHunt

Connect with

No credentials — runs on your own Tentacle

Cadence

Runs on demand — installed on a Tentacle, then invoked during an operation (the agent can install and uninstall it mid-run)

Requires

A Tentacle running Linux or macOS. Free licence, nothing to purchase and no credentials to supply.

// 02

What Cracken gets from GHunt

  • The Gaia ID behind the Google account for an email address

  • Profile photo and cover photo URLs, flagged as custom or default

  • Last profile edit timestamp

  • Account user types

  • Google Chat extended data — entity type and customer ID

  • Google Plus extended data — enterprise-user flag and the list of activated Google services

  • Play Games player profile — username, player ID and avatar URL

  • Google Maps review statistics for the Gaia ID

  • A public Google Calendar and its events, when one exists

  • JSON export from the email, gaia, drive and geolocate modules

// 03

What GHunt does not do

GHunt only returns data for a public Google Account; when the email does not match one, it stops and says so. It also cannot run unattended: it needs an authenticated Google session, set up with the GHunt Companion browser extension, and Cracken supplies no credentials for it, so that sign-in is done by hand.

// 04

How Cracken uses GHunt

  1. 01

    Install GHunt on a Tentacle

  2. 02

    Authenticate GHunt with a Google session

  3. 03

    Run it against a target address and read the result

  4. 04

    Confirm the Tentacle is ready

// 05

Frequently asked questions

What does GHunt find from an email address?

GHunt returns the Gaia ID and public Google profile behind an email address, and inspects Drive items only when handed their link or id.

Does GHunt need a Google account to work?

Yes; GHunt authenticates with Google account session cookies from its own login step, run on a Tentacle in your environment so cookies never leave.

“I've been pretty impressed with how CrackenAGI is able to do its vulnerability discovery, enumeration, reconnaissance, as well as eventually being able to actually execute different exploitation paths.”

Cybersecurity Engineer, red team · test-and-measurement manufacturer

Attack with real GHunt context.

See how Cracken runs GHunt on a Tentacle you host, and proves what it finds end to end.