GREM logo
Focused certification exam prep
Start practice

GREM Certification

TL;DR
  • GREM is GIAC's Reverse Engineering Malware credential, tied to the SANS FOR610 course.
  • The exam has 66 questions, a 3-hour limit, and a 73% minimum passing score.
  • Format mixes multiple-choice with hands-on CyberLive virtual-machine tasks.
  • Exam-only registration costs $999 USD; retakes are $899 after a 30-day wait.

What Is the GREM Certification?

GREM stands for GIAC Reverse Engineering Malware, a certification administered by Global Information Assurance Certification (GIAC). It validates the ability to dissect malicious code - from macro-laced Office documents to packed Windows executables - and determine what a sample actually does. If you're still sorting out the basics, our companion pieces on What Is GREM?, GREM Meaning, and What Does GREM Stand For? cover the acronym and origin in more depth.

This article focuses on the certification itself: how the exam is built, what it costs, which domains you're tested on, and how the credential fits into a malware analysis career. For a broader orientation, see What Is GREM Certification? and What Is A GREM?.

Not a Beginner Badge: GREM assumes comfort with assembly-level thinking and Windows internals. GIAC lists practical work experience, college coursework, and self-paced study as acceptable preparation routes - there is no mandatory training prerequisite, but the material is genuinely technical.

Exam Format and CyberLive Tasks

The GREM exam is a single web-based, proctored assessment: 66 questions, a 3-hour time limit, and a minimum passing score of 73%. What separates it from a purely multiple-choice test is the inclusion of CyberLive tasks - live virtual-machine exercises where you interact with actual tools rather than just answering questions about them.

Delivery happens through ProctorU remote proctoring or at a Pearson VUE test center, depending on how your specific attempt is authorized. Once you activate an attempt, you have 120 days to complete it, and your candidate account will display the exact specifications tied to your registration.

  • Submitted answers cannot be changed once locked in.
  • Skipped or unanswered questions can be revisited before time expires.
  • The exam engine includes a built-in calculator and a scratch notepad for working through byte math, offsets, or logic.
  • It's open book: hardcopy books, printed notes, and an index are allowed. Internet access, personal electronic references, and practice-question collections are not.

For a full breakdown of how the score threshold is calculated and what it means in practice, read GREM Passing Score 2026: Exactly What You Need to Pass. If you're trying to gauge overall difficulty before committing, How Hard Is the GREM Exam? Complete Difficulty Guide 2026 walks through the format's practical challenges, and GREM Pass Rate 2026: What the Data Shows looks at what's publicly known about outcomes.

Key Takeaway

Because CyberLive tasks require you to actually operate analysis tools under time pressure, rehearsing with a real debugger and disassembler matters more than memorizing terminology.

The 15 GREM Domains

GIAC publishes 15 certification-objective domains for GREM. Together they trace the arc of a real malware investigation: static triage, dynamic behavior, document-based malware, obfuscation, and finally assembly-level reversing of packed or anti-analysis-hardened binaries.

Domain 1: Analyzing Malicious Office Macros

Focuses on extracting and interpreting VBA macros embedded in weaponized Office documents.

  • Identifying macro auto-execution triggers
  • De-obfuscating string concatenation and encoded payloads

Domain 2: Analyzing Malicious PDFs

Covers parsing PDF object structures to locate embedded JavaScript and exploit payloads.

  • Recognizing suspicious object streams
  • Extracting and decoding embedded scripts

Domain 3: Analyzing Malicious RTF Files

Deals with RTF-based exploit delivery, a persistent vector for document-based attacks.

  • Spotting malformed control words used to evade detection
  • Locating embedded OLE objects

Domain 4: Analyzing Obfuscated Malware

Tests the ability to see through string encoding, control-flow obfuscation, and junk code.

  • Manual and scripted de-obfuscation techniques

Domain 5: Behavioral Analysis Fundamentals

Covers dynamic analysis: observing what a sample does when executed in a controlled environment.

  • Monitoring registry, file system, and network activity

Domain 6: Common Malware Patterns

Recognizing recurring techniques across malware families - persistence, injection, and staging patterns.

Domain 7: Core Reverse Engineering Concepts

The foundational vocabulary and mental models underlying every other domain.

Domain 8: Examining .NET Malware

Reversing managed-code binaries, which behave differently from native PE files.

  • Decompiling IL to readable pseudocode

Domain 9: Identifying and Bypassing Anti-Analysis Techniques

Covers anti-debugging, anti-VM, and anti-disassembly tricks malware authors deploy.

Domain 10: Malware Analysis Fundamentals

Establishes the overall methodology: triage, environment setup, and safe handling.

Domain 11: Malware Flow Control and Structures

Interpreting branching, loops, and function structures inside disassembled code.

Domain 12: Overcoming Misdirection Techniques

Handling packers, encryptors, and other techniques designed to slow analysis down.

Domain 13: Reversing Functions in Assembly

Reading x86/x64 assembly closely enough to reconstruct function-level logic.

Domain 14: Static Analysis Fundamentals

Examining a binary without executing it - headers, imports, strings, and structure.

Domain 15: Unpacking and Debugging Packed Malware

Using a debugger to unpack runtime-decompressed code and reach the original payload.

Each of these areas deserves individual attention rather than a single pass-through. For a domain-by-domain study breakdown with more detail than fits here, see GREM Exam Domains 2026: Complete Guide to All 15 Content Areas.

Registration, Fees, and Timelines

GIAC prices the GREM exam-only certification attempt at $999 USD before taxes; the associated SANS FOR610 training course is a separate purchase. Once you register, your attempt must be completed within 120 days of activation.

ItemCost / Detail
Exam-only certification attempt$999 USD
Retake attempt$899 (after 30-day waiting period on failure)
Standalone official practice test$399
Attempt extension$479
CPE renewal fee (every 4 years)$499, plus 36 CPEs

These are the only figures GIAC publishes for this credential - don't be confused if you see different numbers attached to a "GREM" elsewhere; other credentials share the acronym but not the pricing. For a complete walkthrough of every fee scenario, including extensions and retakes, read GREM Certification Cost 2026: Complete Pricing Breakdown. Eligibility and prep-route details are covered in GREM Requirements 2026: Eligibility, Prerequisites & How to Qualify, and scheduling logistics around proctoring windows are in GREM Exam Dates 2026: Testing Windows, Deadlines & Scheduling.

Failed Attempt Rule: A failed attempt requires a mandatory 30-day waiting period before you can retake at the $899 retake rate. Plan your first attempt date accordingly rather than assuming you can retest immediately.

Who Hires GREM-Certified Analysts

The skill set behind GREM - reading disassembly, unpacking binaries, tracing obfuscated macros - maps directly onto roles in security operations centers, incident response teams, threat intelligence groups, and dedicated malware research units. Analysts use these skills to determine what a sample does after it's been flagged, write detection signatures, and support attribution work.

Because the domains span everything from Office macro analysis to .NET decompilation and packed-binary unpacking, the certification signals breadth across both document-based and executable-based threats, not just one narrow specialty. For a look at how this translates into compensation ranges and job titles, see GREM Salary Guide 2026: Complete Earnings Analysis and browse current openings referencing the credential in GREM Jobs. If you're weighing whether the investment makes sense for your career stage, Is the GREM Certification Worth It? Complete ROI Analysis 2026 lays out the tradeoffs without relying on invented statistics.

Building a GREM Preparation Path

GIAC lists three acceptable preparation routes: practical work experience, college coursework, and self-paced study. The associated SANS course, FOR610: Reverse-Engineering Malware: Malware Analysis Tools and Techniques, maps closely to the domain list but is optional - the exam itself is what's certified, and training is purchased separately.

A practical way to sequence preparation is to group domains by analysis phase rather than study them in numeric order. Static and behavioral fundamentals come first because every other domain assumes you know how to safely triage a sample before diving deeper.

Weeks 1-2

Fundamentals First

  • Domain 10: Malware Analysis Fundamentals
  • Domain 14: Static Analysis Fundamentals
  • Domain 5: Behavioral Analysis Fundamentals
Weeks 3-4

Document-Based Threats

  • Domain 1: Analyzing Malicious Office Macros
  • Domain 2: Analyzing Malicious PDFs
  • Domain 3: Analyzing Malicious RTF Files
Weeks 5-6

Assembly and Structure

  • Domain 7: Core Reverse Engineering Concepts
  • Domain 13: Reversing Functions in Assembly
  • Domain 11: Malware Flow Control and Structures
Weeks 7-8

Advanced Evasion Topics

  • Domain 4: Analyzing Obfuscated Malware
  • Domain 9: Identifying and Bypassing Anti-Analysis Techniques
  • Domain 12: Overcoming Misdirection Techniques
  • Domain 15: Unpacking and Debugging Packed Malware
  • Domain 8: Examining .NET Malware
  • Domain 6: Common Malware Patterns

Whatever cadence you choose, block time for CyberLive-style rehearsal in the final two weeks - reading about unpacking is not the same as doing it live in a debugger under a clock. A more detailed week-by-week plan, including how to allocate review time before the exam, is in GREM Study Guide 2026: How to Pass on Your First Attempt. For a condensed reference to keep nearby during final review, see GREM Cheat Sheet 2026: One-Page Review of Must-Know Facts.

If you want to test your command-line and tool fluency before exam day, running through practice scenarios on the main practice test platform is a low-risk way to find gaps in unfamiliar domains before they show up on the real attempt.

Key Takeaway

Since answers can't be changed once submitted, practice making a final decision quickly rather than second-guessing - this matters more for a 3-hour, 66-question exam than raw speed alone.

Maintaining the Certification

GREM certification is valid for 4 years. To maintain it, GIAC offers a CPE renewal route requiring 36 CPEs and a standard $499 renewal fee, or alternatively a renewal examination route for those who prefer to retest rather than accumulate continuing education credits.

Given how fast malware packing and anti-analysis techniques evolve, staying current with 36 CPEs over four years is a reasonable way to keep the domains - particularly Domain 9 (Identifying and Bypassing Anti-Analysis Techniques) and Domain 4 (Analyzing Obfuscated Malware) - fresh even after the initial exam is behind you.

Frequently Asked Questions

Is GREM open book?

Yes. Hardcopy books, printed notes, and an index are permitted. Internet access, personal electronic references, and practice-question or answer collections are not allowed during the attempt.

How many questions are on the GREM exam and how long do I have?

The exam has 66 questions combining multiple-choice and hands-on CyberLive tasks, with a 3-hour time limit and a minimum passing score of 73%.

Where can I take the GREM exam?

Delivery is available through ProctorU remote proctoring or Pearson VUE test centers, depending on how your specific attempt is authorized in your candidate account.

What happens if I fail my first attempt?

You must wait 30 days before retaking, and the retake attempt costs $899, separate from the original $999 exam-only fee.

Do I need to take the SANS FOR610 course to sit the exam?

No. GIAC accepts practical work experience, college coursework, and self-paced study as preparation routes; FOR610 training is a separate, optional purchase from the exam-only attempt.

Ready to pass your GREM exam?

Put this into practice with free GREM questions across every exam domain.