- GREM has 15 published domains spanning static, dynamic, and code-level malware analysis.
- The exam is 66 questions, 3 hours, open-book, with a 73% passing score.
- Domains 7, 13, and 15 (core RE, assembly, unpacking) carry the heaviest technical load.
- GIAC does not publish per-domain weighting, so treat every domain as fair game.
What "15 Domains" Actually Means for GREM
When people search for the GIAC Reverse Engineering Malware (GREM) exam, they usually want one thing: a straight answer on what's actually tested. GIAC publishes 15 certification-objective headings for GREM, and those headings are the closest thing to an official syllabus you'll get. There's no glossy blueprint with percentage weights next to each topic - just a list of domain names that map to real skills you need before you sit the proctored exam.
This guide walks through all 15 domains in the order GIAC lists them, explains what each one actually requires you to know, and shows how they connect to the exam format itself: 66 questions, a 3-hour window, a mix of multiple-choice and CyberLive hands-on tasks, and a 73% passing score. If you haven't already, it's worth pairing this domain map with the broader GREM Study Guide 2026: How to Pass on Your First Attempt for a full preparation timeline, and with GREM Passing Score 2026: Exactly What You Need to Pass to understand exactly what 73% means in practice.
The Complete GREM Domain Breakdown
Below are all 15 domains, using GIAC's exact published names, with a plain-language explanation of what each one covers and why it's on the exam.
Domain 1: Analyzing Malicious Office Macros
Covers VBA macro extraction and analysis inside Word and Excel documents, including how attackers use macros as a first-stage dropper.
- Extracting and de-obfuscating VBA code from OLE and OOXML files
- Identifying auto-execution triggers (AutoOpen, Document_Open)
Domain 2: Analyzing Malicious PDFs
Focuses on the PDF object model and how malicious JavaScript, embedded files, and exploit shellcode hide inside seemingly normal documents.
- Parsing PDF object streams and cross-reference tables
- Extracting and analyzing embedded JavaScript payloads
Domain 3: Analyzing Malicious RTF Files
RTF is a common exploit-delivery container. This domain tests your ability to find and analyze embedded OLE objects and exploit code within RTF structures.
- Recognizing RTF control words used to hide payloads
- Extracting embedded objects for further static or dynamic analysis
Domain 4: Analyzing Obfuscated Malware
Tests recognition and manual de-obfuscation of common string, code, and control-flow obfuscation schemes used to slow down analysts.
- Identifying encoded strings and custom encoding routines
- Reconstructing obfuscated logic by hand or with scripting
Domain 5: Behavioral Analysis Fundamentals
Covers dynamic analysis: running a sample in a monitored environment and interpreting process, file, registry, and network activity.
- Using behavioral monitoring tools to build an activity timeline
- Distinguishing benign system noise from malicious behavior
Domain 6: Common Malware Patterns
A knowledge domain covering recurring malware behaviors: persistence mechanisms, injection techniques, C2 patterns, and self-propagation.
- Recognizing common persistence and injection techniques
- Mapping observed behavior to known malware families
Domain 7: Core Reverse Engineering Concepts
The foundational domain underpinning everything else - how disassemblers and debuggers represent code, and how to read that representation accurately.
- Interpreting disassembly output and control-flow graphs
- Understanding compiler-generated code patterns
Domain 8: Examining .NET Malware
Focuses on the unique challenges of analyzing managed-code malware, including decompilation and understanding the .NET execution model.
- Using decompilers to recover near-source-level .NET code
- Recognizing .NET-specific obfuscation and packing
Domain 9: Identifying and Bypassing Anti-Analysis Techniques
Tests your ability to spot and defeat anti-debugging, anti-VM, and anti-disassembly tricks built into malware.
- Recognizing debugger-detection API calls and timing checks
- Patching or bypassing checks to continue analysis
Domain 10: Malware Analysis Fundamentals
Covers the overall methodology and toolset: setting up a safe lab, triaging a sample, and choosing between static and dynamic approaches.
- Building and isolating an analysis environment
- Selecting the right initial triage approach for a given file type
Domain 11: Malware Flow Control and Structures
Examines how malware structures its logic - loops, branching, function calls - and how to trace execution flow through disassembled code.
- Tracing conditional branches and loop constructs in assembly
- Reconstructing high-level logic from low-level flow
Domain 12: Overcoming Misdirection Techniques
Related to but distinct from anti-analysis: covers deliberate red herrings, decoy code, and misleading strings designed to waste analyst time.
- Spotting decoy functions and junk code inserted to mislead
- Prioritizing genuine malicious logic over noise
Domain 13: Reversing Functions in Assembly
A deep, code-level domain requiring comfort reading x86/x64 assembly and mapping instructions back to function-level behavior.
- Reading calling conventions and stack frame setup
- Identifying common API-call patterns at the assembly level
Domain 14: Static Analysis Fundamentals
Covers file-format analysis without execution: PE headers, imports/exports, strings, and packer identification.
- Interpreting PE header fields and section characteristics
- Using import tables to infer sample capability
Domain 15: Unpacking and Debugging Packed Malware
Tests practical unpacking skills: identifying a packer, finding the original entry point, and dumping unpacked code for further analysis.
- Recognizing common packer signatures and behaviors
- Using a debugger to reach OEP and dump unpacked payloads
How These Domains Show Up on Exam Day
Knowing the 15 domain names is only half the picture - you also need to understand the format they're delivered in. The GREM exam is a single web-based, proctored assessment: 66 questions, a 3-hour time limit, and a passing score of 73%. Questions combine standard multiple-choice items with CyberLive tasks, where you interact with a live virtual machine to actually perform analysis steps rather than just answer about them abstractly.
That CyberLive component matters most for the hands-on domains - Domain 5 (Behavioral Analysis Fundamentals), Domain 9 (Identifying and Bypassing Anti-Analysis Techniques), and Domain 15 (Unpacking and Debugging Packed Malware) are exactly the kind of material that lends itself to a practical task rather than a multiple-choice question. If you've only memorized definitions for these domains and never actually run a debugger against a packed sample, that gap will surface quickly during CyberLive sections.
The exam is open-book: you're allowed hardcopy books, printed notes, and an index. What's off-limits is internet access, personal electronic devices, and any pre-made practice-question or answer collections. The exam engine itself includes a built-in calculator and a scratch notepad, but no external references beyond your own paper materials. Once you submit an answer it's locked in, though you can skip a question and come back to it before time runs out.
Key Takeaway
Build a paper index tied to the 15 domains before exam day - not a printout of practice questions. GIAC explicitly prohibits practice-question or answer collections as references, so your index should be your own notes, organized domain by domain, not memorized answer keys.
Delivery happens either via ProctorU remote proctoring or at a Pearson VUE test center, depending on how your specific attempt is authorized. You have 120 days from activation to complete the attempt, and your candidate account will show the exact specifications tied to your registration. For a full walkthrough of these logistics, see GREM Exam Dates 2026: Testing Windows, Deadlines & Scheduling.
Domain Weighting: Why GIAC Doesn't Publish Percentages
Unlike some certification programs that break down "20% Domain A, 15% Domain B," GIAC's public GREM materials list the 15 domain names without assigned percentages. That's a deliberate design choice across GIAC certifications generally, and it has a practical implication for your prep: you can't safely deprioritize any domain based on an assumed low weight.
What you can do is group the domains by the type of cognitive demand they place on you, which helps you allocate study time more sensibly even without official weighting:
| Domain Group | Domains Included | Primary Skill Type |
|---|---|---|
| File-format & document analysis | 1, 2, 3, 14 | Static structural analysis |
| Code-level reverse engineering | 7, 11, 13 | Assembly reading, control flow |
| Evasion & obfuscation | 4, 9, 12 | Recognizing and defeating tricks |
| Execution-based analysis | 5, 10, 15 | Dynamic/hands-on lab work |
| Specialized runtime | 6, 8 | Pattern knowledge, .NET internals |
This grouping isn't an official GIAC framework - it's a practical lens for study planning. For a deeper dive into how difficult candidates generally find each cluster, check How Hard Is the GREM Exam? Complete Difficulty Guide 2026, and for context on overall pass outcomes, see GREM Pass Rate 2026: What the Data Shows.
Sequencing the 15 Domains Into a Study Plan
Rather than studying the domains in the order GIAC lists them, it makes more sense to build foundational skills first and layer specialized topics on top. Domain 7 (Core Reverse Engineering Concepts) and Domain 10 (Malware Analysis Fundamentals) underpin nearly everything else, so they belong at the start of any study sequence, not the end.
Foundations
- Domain 10: Malware Analysis Fundamentals - lab setup, triage methodology
- Domain 14: Static Analysis Fundamentals - PE headers, imports, strings
- Domain 7: Core Reverse Engineering Concepts - disassembler literacy
Document-Based Malware
- Domain 1: Analyzing Malicious Office Macros
- Domain 2: Analyzing Malicious PDFs
- Domain 3: Analyzing Malicious RTF Files
Code-Level Skills
- Domain 13: Reversing Functions in Assembly
- Domain 11: Malware Flow Control and Structures
- Domain 8: Examining .NET Malware
Evasion, Behavior, and Unpacking
- Domain 4: Analyzing Obfuscated Malware
- Domain 9: Identifying and Bypassing Anti-Analysis Techniques
- Domain 12: Overcoming Misdirection Techniques
- Domain 5: Behavioral Analysis Fundamentals
- Domain 15: Unpacking and Debugging Packed Malware
- Domain 6: Common Malware Patterns
Whatever cadence you use, tie your review sessions to specific domains rather than vague "review everything" blocks - a weekly schedule anchored to domain names is far more effective for a 15-domain, hands-on exam like this than generic flashcard cycling. Practicing against realistic questions that mirror the CyberLive format, such as through reverseengineeringexam.com's practice tests, helps confirm whether your domain-by-domain understanding actually translates into exam performance.
Who Actually Tests You on This Material
GREM is tied to the SANS FOR610: Reverse-Engineering Malware course, and the exam content reflects the kind of work performed by malware analysts, incident responders, and threat intelligence teams who need to take apart a suspicious binary or document and explain exactly what it does. If you're evaluating whether investing in this specific skill set makes sense for your career, the domain list above is a useful gut-check: if terms like OEP, control-flow graph, and calling convention feel unfamiliar, that's a signal for how much runway you'll need.
For broader context on career fit and compensation expectations, see GREM Jobs and GREM Salary Guide 2026: Complete Earnings Analysis. If you're still deciding whether to pursue the credential at all, Is the GREM Certification Worth It? Complete ROI Analysis 2026 and GREM Certification Cost 2026: Complete Pricing Breakdown lay out the full cost picture, including the $999 exam-only attempt, $899 retake fee, $399 practice test, and $479 extension option, separate from any training purchase.
If you're new to the credential entirely and want the basics before diving into domains, start with What Is GREM Certification? or GREM Certification for an overview, and GREM Requirements 2026: Eligibility, Prerequisites & How to Qualify for prerequisite and eligibility details. GIAC lists practical work experience, college coursework, and self-paced study as valid preparation routes alongside formal training.
FAQ
No. GIAC lists the 15 domain names as published certification objectives but does not release a percentage breakdown of how many questions come from each domain.
GIAC doesn't map specific domains to specific question types publicly, but hands-on domains like Behavioral Analysis Fundamentals, Unpacking and Debugging Packed Malware, and Identifying and Bypassing Anti-Analysis Techniques are well-suited to CyberLive virtual-machine tasks.
Yes. The GREM exam is open-book, allowing hardcopy books, printed notes, and an index. Internet access, personal electronic devices, and practice-question collections are not permitted.
Since GIAC does not publish domain weighting, it's safest to treat all 15 domains as equally essential rather than assuming any one is more heavily tested.
You risk gaps on exam day since the 66 questions can draw from any of the 15 domains. Prioritize foundational domains like Core Reverse Engineering Concepts and Malware Analysis Fundamentals first, since they support understanding across the rest.