- GREM is GIAC's Reverse Engineering Malware credential, tied to the SANS FOR610 course.
- The exam has 66 questions, a 3-hour limit, and a 73% minimum passing score.
- Format mixes multiple-choice with hands-on CyberLive virtual-machine tasks.
- Exam-only registration costs $999 USD; retakes are $899 after a 30-day wait.
What Is the GREM Certification?
GREM stands for GIAC Reverse Engineering Malware, a certification administered by Global Information Assurance Certification (GIAC). It validates the ability to dissect malicious code - from macro-laced Office documents to packed Windows executables - and determine what a sample actually does. If you're still sorting out the basics, our companion pieces on What Is GREM?, GREM Meaning, and What Does GREM Stand For? cover the acronym and origin in more depth.
This article focuses on the certification itself: how the exam is built, what it costs, which domains you're tested on, and how the credential fits into a malware analysis career. For a broader orientation, see What Is GREM Certification? and What Is A GREM?.
Exam Format and CyberLive Tasks
The GREM exam is a single web-based, proctored assessment: 66 questions, a 3-hour time limit, and a minimum passing score of 73%. What separates it from a purely multiple-choice test is the inclusion of CyberLive tasks - live virtual-machine exercises where you interact with actual tools rather than just answering questions about them.
Delivery happens through ProctorU remote proctoring or at a Pearson VUE test center, depending on how your specific attempt is authorized. Once you activate an attempt, you have 120 days to complete it, and your candidate account will display the exact specifications tied to your registration.
- Submitted answers cannot be changed once locked in.
- Skipped or unanswered questions can be revisited before time expires.
- The exam engine includes a built-in calculator and a scratch notepad for working through byte math, offsets, or logic.
- It's open book: hardcopy books, printed notes, and an index are allowed. Internet access, personal electronic references, and practice-question collections are not.
For a full breakdown of how the score threshold is calculated and what it means in practice, read GREM Passing Score 2026: Exactly What You Need to Pass. If you're trying to gauge overall difficulty before committing, How Hard Is the GREM Exam? Complete Difficulty Guide 2026 walks through the format's practical challenges, and GREM Pass Rate 2026: What the Data Shows looks at what's publicly known about outcomes.
Key Takeaway
Because CyberLive tasks require you to actually operate analysis tools under time pressure, rehearsing with a real debugger and disassembler matters more than memorizing terminology.
The 15 GREM Domains
GIAC publishes 15 certification-objective domains for GREM. Together they trace the arc of a real malware investigation: static triage, dynamic behavior, document-based malware, obfuscation, and finally assembly-level reversing of packed or anti-analysis-hardened binaries.
Domain 1: Analyzing Malicious Office Macros
Focuses on extracting and interpreting VBA macros embedded in weaponized Office documents.
- Identifying macro auto-execution triggers
- De-obfuscating string concatenation and encoded payloads
Domain 2: Analyzing Malicious PDFs
Covers parsing PDF object structures to locate embedded JavaScript and exploit payloads.
- Recognizing suspicious object streams
- Extracting and decoding embedded scripts
Domain 3: Analyzing Malicious RTF Files
Deals with RTF-based exploit delivery, a persistent vector for document-based attacks.
- Spotting malformed control words used to evade detection
- Locating embedded OLE objects
Domain 4: Analyzing Obfuscated Malware
Tests the ability to see through string encoding, control-flow obfuscation, and junk code.
- Manual and scripted de-obfuscation techniques
Domain 5: Behavioral Analysis Fundamentals
Covers dynamic analysis: observing what a sample does when executed in a controlled environment.
- Monitoring registry, file system, and network activity
Domain 6: Common Malware Patterns
Recognizing recurring techniques across malware families - persistence, injection, and staging patterns.
Domain 7: Core Reverse Engineering Concepts
The foundational vocabulary and mental models underlying every other domain.
Domain 8: Examining .NET Malware
Reversing managed-code binaries, which behave differently from native PE files.
- Decompiling IL to readable pseudocode
Domain 9: Identifying and Bypassing Anti-Analysis Techniques
Covers anti-debugging, anti-VM, and anti-disassembly tricks malware authors deploy.
Domain 10: Malware Analysis Fundamentals
Establishes the overall methodology: triage, environment setup, and safe handling.
Domain 11: Malware Flow Control and Structures
Interpreting branching, loops, and function structures inside disassembled code.
Domain 12: Overcoming Misdirection Techniques
Handling packers, encryptors, and other techniques designed to slow analysis down.
Domain 13: Reversing Functions in Assembly
Reading x86/x64 assembly closely enough to reconstruct function-level logic.
Domain 14: Static Analysis Fundamentals
Examining a binary without executing it - headers, imports, strings, and structure.
Domain 15: Unpacking and Debugging Packed Malware
Using a debugger to unpack runtime-decompressed code and reach the original payload.
Each of these areas deserves individual attention rather than a single pass-through. For a domain-by-domain study breakdown with more detail than fits here, see GREM Exam Domains 2026: Complete Guide to All 15 Content Areas.
Registration, Fees, and Timelines
GIAC prices the GREM exam-only certification attempt at $999 USD before taxes; the associated SANS FOR610 training course is a separate purchase. Once you register, your attempt must be completed within 120 days of activation.
| Item | Cost / Detail |
|---|---|
| Exam-only certification attempt | $999 USD |
| Retake attempt | $899 (after 30-day waiting period on failure) |
| Standalone official practice test | $399 |
| Attempt extension | $479 |
| CPE renewal fee (every 4 years) | $499, plus 36 CPEs |
These are the only figures GIAC publishes for this credential - don't be confused if you see different numbers attached to a "GREM" elsewhere; other credentials share the acronym but not the pricing. For a complete walkthrough of every fee scenario, including extensions and retakes, read GREM Certification Cost 2026: Complete Pricing Breakdown. Eligibility and prep-route details are covered in GREM Requirements 2026: Eligibility, Prerequisites & How to Qualify, and scheduling logistics around proctoring windows are in GREM Exam Dates 2026: Testing Windows, Deadlines & Scheduling.
Who Hires GREM-Certified Analysts
The skill set behind GREM - reading disassembly, unpacking binaries, tracing obfuscated macros - maps directly onto roles in security operations centers, incident response teams, threat intelligence groups, and dedicated malware research units. Analysts use these skills to determine what a sample does after it's been flagged, write detection signatures, and support attribution work.
Because the domains span everything from Office macro analysis to .NET decompilation and packed-binary unpacking, the certification signals breadth across both document-based and executable-based threats, not just one narrow specialty. For a look at how this translates into compensation ranges and job titles, see GREM Salary Guide 2026: Complete Earnings Analysis and browse current openings referencing the credential in GREM Jobs. If you're weighing whether the investment makes sense for your career stage, Is the GREM Certification Worth It? Complete ROI Analysis 2026 lays out the tradeoffs without relying on invented statistics.
Building a GREM Preparation Path
GIAC lists three acceptable preparation routes: practical work experience, college coursework, and self-paced study. The associated SANS course, FOR610: Reverse-Engineering Malware: Malware Analysis Tools and Techniques, maps closely to the domain list but is optional - the exam itself is what's certified, and training is purchased separately.
A practical way to sequence preparation is to group domains by analysis phase rather than study them in numeric order. Static and behavioral fundamentals come first because every other domain assumes you know how to safely triage a sample before diving deeper.
Fundamentals First
- Domain 10: Malware Analysis Fundamentals
- Domain 14: Static Analysis Fundamentals
- Domain 5: Behavioral Analysis Fundamentals
Document-Based Threats
- Domain 1: Analyzing Malicious Office Macros
- Domain 2: Analyzing Malicious PDFs
- Domain 3: Analyzing Malicious RTF Files
Assembly and Structure
- Domain 7: Core Reverse Engineering Concepts
- Domain 13: Reversing Functions in Assembly
- Domain 11: Malware Flow Control and Structures
Advanced Evasion Topics
- Domain 4: Analyzing Obfuscated Malware
- Domain 9: Identifying and Bypassing Anti-Analysis Techniques
- Domain 12: Overcoming Misdirection Techniques
- Domain 15: Unpacking and Debugging Packed Malware
- Domain 8: Examining .NET Malware
- Domain 6: Common Malware Patterns
Whatever cadence you choose, block time for CyberLive-style rehearsal in the final two weeks - reading about unpacking is not the same as doing it live in a debugger under a clock. A more detailed week-by-week plan, including how to allocate review time before the exam, is in GREM Study Guide 2026: How to Pass on Your First Attempt. For a condensed reference to keep nearby during final review, see GREM Cheat Sheet 2026: One-Page Review of Must-Know Facts.
If you want to test your command-line and tool fluency before exam day, running through practice scenarios on the main practice test platform is a low-risk way to find gaps in unfamiliar domains before they show up on the real attempt.
Key Takeaway
Since answers can't be changed once submitted, practice making a final decision quickly rather than second-guessing - this matters more for a 3-hour, 66-question exam than raw speed alone.
Maintaining the Certification
GREM certification is valid for 4 years. To maintain it, GIAC offers a CPE renewal route requiring 36 CPEs and a standard $499 renewal fee, or alternatively a renewal examination route for those who prefer to retest rather than accumulate continuing education credits.
Given how fast malware packing and anti-analysis techniques evolve, staying current with 36 CPEs over four years is a reasonable way to keep the domains - particularly Domain 9 (Identifying and Bypassing Anti-Analysis Techniques) and Domain 4 (Analyzing Obfuscated Malware) - fresh even after the initial exam is behind you.
Frequently Asked Questions
Yes. Hardcopy books, printed notes, and an index are permitted. Internet access, personal electronic references, and practice-question or answer collections are not allowed during the attempt.
The exam has 66 questions combining multiple-choice and hands-on CyberLive tasks, with a 3-hour time limit and a minimum passing score of 73%.
Delivery is available through ProctorU remote proctoring or Pearson VUE test centers, depending on how your specific attempt is authorized in your candidate account.
You must wait 30 days before retaking, and the retake attempt costs $899, separate from the original $999 exam-only fee.
No. GIAC accepts practical work experience, college coursework, and self-paced study as preparation routes; FOR610 training is a separate, optional purchase from the exam-only attempt.