- GREM is one 66-question, 3-hour exam with a 73% passing score, mixing multiple-choice with CyberLive VM tasks.
- The exam is open book, but internet access and practice-question collections are strictly prohibited.
- You have 120 days from activation to sit the exam, so schedule study around that window immediately.
- The 15 published domains span static analysis, PDF/Office/RTF malware, unpacking, .NET, and anti-analysis evasion.
What GREM Actually Tests
GIAC Reverse Engineering Malware (GREM) is a GIAC certification built around one core question: can you take a piece of malicious code - an Office macro, a PDF, a packed Windows binary, a .NET sample - and determine what it does, how it hides, and how it survives analysis? If you're still unclear on the basics of the acronym or the sponsoring body, start with What Is GREM? and GREM Meaning before diving into exam mechanics.
Unlike certifications that test broad security knowledge, GREM is narrow and technical by design. The associated training, SANS FOR610: Reverse-Engineering Malware, focuses on tools and techniques rather than theory, and the exam mirrors that hands-on orientation through its CyberLive virtual-machine tasks embedded alongside multiple-choice questions.
Exam Mechanics You Must Plan Around
Before building a study plan, internalize the exact format. GREM is a single web-based, proctored exam consisting of 66 questions delivered over 3 hours. You need a minimum score of 73% to pass. Some questions are traditional multiple-choice; others are CyberLive tasks that drop you into a live virtual machine environment where you actually perform analysis steps rather than just answering about them.
You can sit the exam through ProctorU remote proctoring or at a Pearson VUE test center, depending on how your specific attempt is authorized. Once you activate your attempt, the clock starts on a 120-day window to complete it - plan your study calendar backward from that date, not forward from "whenever I feel ready."
Two answer-handling rules matter for exam-day strategy:
- Once you submit an answer, it cannot be changed.
- Skipped, unanswered questions can be revisited later in the attempt.
The exam engine includes a built-in calculator and scratch notepad - useful for offset math, byte calculations, or jotting down instruction sequences while working through a CyberLive task. For a deeper look at exactly how the 73% threshold is calculated and why it matters more than raw question count, see GREM Passing Score 2026: Exactly What You Need to Pass.
Key Takeaway
Because submitted answers are locked in immediately, treat every multiple-choice question as final. Use the "skip and revisit" option liberally on ambiguous CyberLive tasks rather than guessing under time pressure.
Breaking Down the 15 Domains
GIAC publishes 15 domain headings for GREM, and your study plan should be organized around these exact areas rather than a generic malware-analysis curriculum. A full walkthrough of each domain with study angles lives in GREM Exam Domains 2026: Complete Guide to All 15 Content Areas; here's how to think about the highest-leverage clusters.
Static & Behavioral Foundations
Domains 10 and 14 - Malware Analysis Fundamentals and Static Analysis Fundamentals - establish the vocabulary and triage process the rest of the exam builds on. Domain 5, Behavioral Analysis Fundamentals, covers observing a sample's runtime actions without fully reverse engineering it.
- Know the difference between static indicators and behavioral indicators
- Be comfortable with file-type identification and initial triage workflows
File-Format-Specific Analysis
Three domains focus entirely on document-based malware: Analyzing Malicious Office Macros (Domain 1), Analyzing Malicious PDFs (Domain 2), and Analyzing Malicious RTF Files (Domain 3). These are heavily weighted toward practical extraction and deobfuscation of embedded scripts and objects.
- Practice pulling and deobfuscating VBA macros manually
- Understand PDF object structure and common exploitation patterns
- Recognize RTF-specific embedding and exploit delivery mechanisms
Binary-Level Reverse Engineering
Core Reverse Engineering Concepts (Domain 7), Reversing Functions in Assembly (Domain 13), and Malware Flow Control and Structures (Domain 11) form the technical core of the exam. Expect to read disassembly, trace control flow, and identify function-level logic patterns under time pressure - often via CyberLive tasks rather than multiple-choice.
- Drill assembly-level function prologues, epilogues, and common calling conventions
- Practice mapping control-flow graphs from disassembled code
Evasion, Packing, and Modern Formats
Domains 4, 9, 12, and 15 - Analyzing Obfuscated Malware, Identifying and Bypassing Anti-Analysis Techniques, Overcoming Misdirection Techniques, and Unpacking and Debugging Packed Malware - test your ability to defeat the countermeasures malware authors build in. Domain 8, Examining .NET Malware, adds a managed-code dimension with its own tooling. Domain 6, Common Malware Patterns, ties recurring behaviors across all of these together.
- Practice identifying packer signatures and manual unpacking with a debugger
- Know common anti-debugging and anti-VM checks and how to bypass them
- Get comfortable with .NET-specific decompilation tools and IL structure
If you're trying to gauge how tough this domain spread is compared to other technical certifications, How Hard Is the GREM Exam? Complete Difficulty Guide 2026 breaks down the difficulty drivers domain by domain.
A GREM-Specific Study Timeline
Generic study methodology only goes so far here - what matters is sequencing GREM's domains in an order that builds skill logically, from triage to full reverse engineering. Use this as a starting framework and adjust based on your existing tool familiarity.
Foundations
- Malware Analysis Fundamentals and Static Analysis Fundamentals
- Set up your lab: disassembler, debugger, .NET decompiler, PDF/Office analysis tools
File-Format Malware
- Analyzing Malicious Office Macros, PDFs, and RTF Files
- Behavioral Analysis Fundamentals alongside document-based samples
Binary Reverse Engineering
- Core Reverse Engineering Concepts, Reversing Functions in Assembly, Malware Flow Control and Structures
- Common Malware Patterns as a running reference across samples
Evasion and Advanced Formats
- Unpacking and Debugging Packed Malware, Identifying and Bypassing Anti-Analysis Techniques
- Overcoming Misdirection Techniques, Analyzing Obfuscated Malware, Examining .NET Malware
CyberLive Simulation & Review
- Timed practice under open-book conditions across all 15 domains
- Build and refine your index (see next section)
For a condensed, one-page reference to keep nearby during this final review stretch, see the GREM Cheat Sheet 2026: One-Page Review of Must-Know Facts.
Building Your Open-Book Index
GREM's open-book policy is one of its most distinctive features, and it should shape how you study - not replace studying. You're permitted to bring hardcopy books, notes, and an index into the exam. What you cannot bring is internet access, personal electronic references, or any collection of practice questions and answers.
This means your value-add during study time is building a well-organized, tabbed index across the 15 domains - not memorizing every disassembly mnemonic cold. Structure your index by domain name (matching GIAC's published headings exactly) so you can flip to the right section fast under a 3-hour clock.
Registration, Cost, and Retake Mechanics
Understanding the financial and scheduling mechanics of GREM prevents avoidable stress. The exam-only certification attempt costs $999 USD before taxes, and training through SANS FOR610 is a separate purchase - you don't have to bundle them. GIAC also recognizes practical work experience, college coursework, and self-paced study as valid preparation routes, so formal training is not mandatory. Full eligibility details are covered in GREM Requirements 2026: Eligibility, Prerequisites & How to Qualify.
If you don't pass on the first try, a retake costs $899, but you must wait 30 days after a failed attempt before retaking. A standalone official practice test is available for $399, and if you need more time within your attempt window, an extension costs $479. Every one of these numbers, plus how they interact, is broken down further in GREM Certification Cost 2026: Complete Pricing Breakdown.
| Item | Cost | Notes |
|---|---|---|
| Exam-only certification attempt | $999 | Before taxes; training purchased separately |
| Retake | $899 | 30-day waiting period after a fail |
| Standalone official practice test | $399 | Separate from the certification attempt |
| Attempt extension | $479 | Extends within your activation period |
Once activated, remember your attempt must be completed within 120 days, and delivery happens via ProctorU or Pearson VUE as authorized for your specific registration. Check GREM Exam Dates 2026: Testing Windows, Deadlines & Scheduling for guidance on scheduling around this window without rushing your prep.
Key Takeaway
Budget for one retake in your planning even if you're confident. Building the $899 retake fee and 30-day wait into your timeline removes panic if the CyberLive tasks run tighter on time than expected.
Who Hires GREM Holders
GREM sits squarely in the malware analysis and reverse engineering niche of security work - roles like malware analyst, threat intelligence analyst, incident responder with a deep-dive analysis function, and reverse engineer on a vulnerability or detection-engineering team. Because the exam objectives map directly to tasks like unpacking binaries, deobfuscating macros, and bypassing anti-analysis checks, it signals hands-on capability rather than managerial or policy knowledge.
If you're weighing whether this specialization fits your career goals, Is the GREM Certification Worth It? Complete ROI Analysis 2026 and GREM Salary Guide 2026: Complete Earnings Analysis go further into how the certification is positioned in the job market, and GREM Jobs looks at typical role titles that reference this credential.
Common First-Attempt Mistakes
Most first-attempt failures on technical GIAC exams trace back to preparation gaps rather than exam-day panic. For GREM specifically, watch for these patterns:
- Treating it like a multiple-choice-only exam. CyberLive tasks require you to actually perform analysis steps in a live environment - passive reading knowledge isn't enough.
- Skipping the document-format domains. Candidates with strong binary reverse engineering skills sometimes under-prepare for Analyzing Malicious Office Macros, PDFs, and RTF Files, which are distinct skill sets from assembly-level work.
- Building an unindexed pile of notes. An open-book policy only helps if your reference material is organized by domain and quickly searchable under time pressure.
- Ignoring the 120-day clock. Activating the attempt before you're ready to commit to a structured schedule wastes valuable time.
- Underestimating .NET and packed-binary questions. Examining .NET Malware and Unpacking and Debugging Packed Malware require distinct toolchains that some candidates never practice with hands-on.
For a broader look at how these mistakes affect outcomes across the candidate pool, see GREM Pass Rate 2026: What the Data Shows. And if you haven't yet nailed down basic terminology around the credential itself, What Does GREM Stand For?, What Is A GREM?, and What Does GREM Mean? clear up naming confusion before you start deeper technical study.
Throughout your preparation, pairing domain study with realistic practice questions on our GREM practice test platform helps translate reading into exam-ready recall - especially useful for rehearsing the CyberLive-style task format under time constraints. You can also review the fundamentals of the GREM Certification and the full What Is GREM Certification? overview before locking in your registration date.
FAQ
The GREM exam has 66 questions to complete within 3 hours, delivered as a single web-based proctored attempt combining multiple-choice and CyberLive virtual-machine tasks.
You need a minimum passing score of 73%. See GREM Passing Score 2026 for more detail on how this threshold is applied.
Yes, GREM is open book. You may bring hardcopy books, notes, and an index, but internet access, personal electronic references, and practice-question or answer collections are prohibited.
You must wait 30 days before retaking, and the retake fee is $899. Budgeting for this possibility keeps your prep timeline realistic.
No. Training is a separate purchase from the exam-only attempt, and GIAC also recognizes practical work experience, college coursework, and self-paced study as preparation routes. See GREM Training for more on how the course maps to the exam.