GREM logo
Focused certification exam prep
Start practice

GREM Training

TL;DR
  • GIAC lists three prep routes for GREM: SANS FOR610 training, practical work experience, or self-paced study.
  • The exam is 66 questions in 3 hours with a 73% passing score, mixing multiple-choice and CyberLive VM tasks.
  • Exam-only registration is $999; training itself is purchased separately from the certification attempt.
  • All 15 published domains, from Office macros to unpacking, deserve dedicated lab time, not just reading.

What Counts as GREM Training

GREM training refers to the preparation work a candidate does before sitting the GIAC Reverse Engineering Malware exam. GIAC does not require candidates to take a specific course before registering for the exam. Instead, GIAC publishes three acceptable preparation routes: formal training through the associated course, practical work experience in malware analysis, and self-paced study using books, whitepapers, and lab practice. Whichever route you choose, "training" for GREM ultimately means building hands-on reverse-engineering skill across the 15 published domains, not memorizing trivia.

Because the exam draws from a specific set of certification objectives, effective training is structured around those objectives rather than around generic security topics. If you haven't reviewed the objectives in detail yet, the GREM Exam Domains 2026: Complete Guide to All 15 Content Areas breaks down what each domain actually tests, which is the natural starting point before you build a study plan.

Training Is Separate From Certification: The exam-only attempt is priced separately from any training purchase. You can register for the GREM exam without ever purchasing a course, provided you're confident your self-study or work experience covers the domains.

FOR610 Training vs. Self-Study Preparation

The training most commonly associated with GREM is SANS FOR610: Reverse-Engineering Malware: Malware Analysis Tools and Techniques. This course is GIAC's listed associated training for the certification, and it's built to walk through the same categories of skill the exam objectives cover, from static analysis to behavioral analysis to unpacking. Taking the associated course gives you structured labs and an instructor-guided path through material that otherwise takes significant self-direction to assemble.

That said, GIAC explicitly recognizes practical work experience and self-paced study as valid alternatives. If you already work in malware analysis, incident response, or a SOC role that involves disassembly and debugging, your day-to-day experience may already cover several domains. In that case, training time is better spent filling specific gaps - for example, .NET malware analysis or anti-analysis bypass techniques - rather than repeating skills you already use at work.

For a candid look at how demanding this preparation actually is regardless of route, see How Hard Is the GREM Exam? Complete Difficulty Guide 2026, which walks through the skill gap between general security knowledge and the reverse-engineering depth GREM expects.

Key Takeaway

Choose your training route based on your current skill gaps, not on what's most popular. Someone who already debugs malware daily needs different training than someone entering reverse engineering for the first time.

Mapping Training to the 15 GREM Domains

GIAC publishes 15 domain headings for GREM, and each one represents a distinct skill set an examiner expects you to demonstrate - often through a hands-on CyberLive task rather than a simple recall question. Training that ignores any of these areas leaves a real gap on exam day.

Domain 1: Analyzing Malicious Office Macros

Candidates need to extract and de-obfuscate VBA macros, identify malicious API calls, and trace execution from document open to payload delivery.

  • Practice with real macro-enabled document samples in an isolated VM

Domain 2 & 3: Analyzing Malicious PDFs and RTF Files

These formats require understanding embedded objects, JavaScript execution paths, and exploit-delivery structures unique to each file type.

  • Train on extracting embedded streams and objects with static-analysis tooling

Domain 4, 9 & 12: Obfuscation, Anti-Analysis, and Misdirection

These three domains overlap heavily in practice. Training should cover recognizing packers, string obfuscation, anti-debugging checks, and techniques malware authors use to mislead an analyst.

  • Build familiarity with common obfuscation patterns before attempting timed labs

Domain 7 & 13: Core Reverse Engineering Concepts and Assembly Functions

This is the foundational layer underneath every other domain. Weak assembly-reading skills will slow you down across the entire exam.

  • Drill function prologues, calling conventions, and control-flow reconstruction in a disassembler

Domain 8: Examining .NET Malware

.NET binaries decompile differently than native code, and training here should include working with decompilers built for managed code rather than treating every sample as native x86.

  • Practice recovering readable source-like logic from .NET assemblies

Domain 15: Unpacking and Debugging Packed Malware

Packed samples are common in real malware, and this domain tests whether you can identify a packer, set breakpoints strategically, and dump unpacked code for further analysis.

  • Rehearse manual unpacking workflows, not just automated unpacker tools

Domains 5, 6, 10, 11, and 14 - Behavioral Analysis Fundamentals, Common Malware Patterns, Malware Analysis Fundamentals, Malware Flow Control and Structures, and Static Analysis Fundamentals - form the connective tissue that ties the more specialized domains together. Training time here should focus on building a repeatable analysis methodology you can apply consistently across sample types. For a complete walkthrough of how these 15 areas interrelate, revisit the GREM Exam Domains 2026: Complete Guide to All 15 Content Areas.

Training for the Exam Format Itself

Domain knowledge alone isn't sufficient - part of GREM training is getting comfortable with the exam's specific format. The exam is web-based and proctored, delivered through either ProctorU remote proctoring or Pearson VUE test centers depending on how your attempt is authorized. It consists of 66 questions to be completed in 3 hours, combining traditional multiple-choice questions with hands-on CyberLive virtual-machine tasks where you interact with a live environment rather than just selecting an answer.

The minimum passing score is 73%. Because the exam is open book - hardcopy books, notes, and an index are permitted, though internet access, personal electronic devices, and practice-question collections are prohibited - training should include building a well-organized physical index you can navigate quickly under time pressure. An exam that allows references but limits you to 3 hours across 66 items rewards fast retrieval far more than memorization.

Answer Mechanics Matter: Submitted answers cannot be changed once entered, but skipped questions can be revisited later in the attempt. Train yourself to skip uncertain CyberLive tasks early and return to them rather than losing time on a single question.

The exam engine also provides a built-in calculator and scratch notepad - small tools, but worth practicing with in any mock exam environment you build, since fumbling with unfamiliar interface elements costs real minutes. For a deeper breakdown of exactly what 73% means in practice and how the scoring works, see GREM Passing Score 2026: Exactly What You Need to Pass.

Building a Malware Analysis Lab

No amount of reading substitutes for hands-on time inside a disassembler, debugger, and decompiler, especially given how many CyberLive tasks appear on the exam. A functional home lab for GREM training typically includes:

  • An isolated virtual machine environment for safely detonating and observing malware samples
  • A disassembler and debugger for static and dynamic native-code analysis
  • A .NET decompiler for Domain 8 preparation
  • Tools for extracting and analyzing Office macros, PDF objects, and RTF structures
  • A packing/unpacking workflow you can repeat consistently for Domain 15

Set up this lab early in your training timeline rather than during the final review weeks. Troubleshooting tool configuration under exam-week pressure wastes time that should go toward actual sample analysis.

A Domain-Sequenced Training Timeline

Generic study techniques like spaced repetition or timeboxed review sessions only help when they're mapped onto GREM's actual domain structure. Below is one way to sequence training across several weeks, prioritizing foundational domains before specialized ones.

Weeks 1-2

Foundations

  • Core Reverse Engineering Concepts, Static Analysis Fundamentals, Malware Analysis Fundamentals
  • Set up lab tooling and practice basic disassembly
Weeks 3-4

Assembly and Behavior

  • Reversing Functions in Assembly, Behavioral Analysis Fundamentals, Malware Flow Control and Structures
Weeks 5-6

Document-Based Threats

  • Analyzing Malicious Office Macros, PDFs, and RTF Files
  • Practice extraction and de-obfuscation on real samples
Weeks 7-8

Evasion and Advanced Topics

  • Analyzing Obfuscated Malware, Identifying and Bypassing Anti-Analysis Techniques, Overcoming Misdirection Techniques
  • Unpacking and Debugging Packed Malware, Examining .NET Malware
Weeks 9-10

Integration and Timed Practice

  • Common Malware Patterns review, full-length timed practice runs, index refinement

This sequencing is only a starting framework - adjust the pacing to your background. For a more detailed week-by-week strategy including how to allocate review time near the end of your attempt window, see the GREM Study Guide 2026: How to Pass on Your First Attempt.

Training Costs and Registration Mechanics

Understanding the fee structure helps you plan training investment realistically. The exam-only certification attempt is $999 USD before taxes, and training is purchased separately from that fee. If your first attempt doesn't succeed, a retake costs $899, and a mandatory 30-day waiting period applies before you can sit again - which makes thorough training before your first attempt more valuable than rushing in and relying on a retake.

GIAC also offers a standalone official practice test for $399, useful as a diagnostic tool to identify weak domains before exam day, and an attempt extension for $479 if you need more time within your access window. Once your attempt is activated, you have 120 days to complete it, and your candidate account will display the attempt-specific exam specifications relevant to your registration.

ItemCost
Exam-only certification attempt$999 USD
Retake (after failed attempt)$899
Standalone official practice test$399
Attempt extension$479
CPE renewal (every 4 years, 36 CPEs required)$499

For a full breakdown of every fee alongside training cost considerations, read GREM Certification Cost 2026: Complete Pricing Breakdown. And if you're still confirming that your background meets what's expected before registering, check GREM Requirements 2026: Eligibility, Prerequisites & How to Qualify.

Who Pursues GREM Training and Why

GREM training tends to attract malware analysts, incident responders, threat intelligence analysts, and digital forensics professionals who need to move from "detecting" malware to actually dissecting it. Because the certification centers on reverse engineering rather than broad security operations, it appeals specifically to people whose job requires reading disassembled code, tracing obfuscated logic, and unpacking samples by hand - not generalist security roles.

If you're evaluating whether this specialization fits your career path before committing training time and exam fees, Is the GREM Certification Worth It? Complete ROI Analysis 2026 and GREM Jobs both cover how the credential is used in practice. For a look at how the role and skill set typically translate into compensation, see GREM Salary Guide 2026: Complete Earnings Analysis.

Once your training is well underway, it's worth running full practice attempts under realistic time constraints. You can find a broader set of practice resources on the main practice test site to simulate the pacing of a 66-question, 3-hour attempt before you commit to a real registration date.

Key Takeaway

Training that mirrors the exam's mix of multiple-choice and CyberLive tasks will expose weaknesses that flashcards alone never will. Prioritize lab time over passive reading in your final weeks.

Frequently Asked Questions

Is SANS FOR610 required before I can take the GREM exam?

No. GIAC lists FOR610 as the associated training course, but practical work experience and self-paced study are also recognized preparation routes for the GREM exam.

Does the GREM exam fee include training?

No. The exam-only certification attempt is $999 USD before taxes, and any training course is purchased separately.

How long do I have to complete training and take the exam once I register?

You must complete your exam attempt within 120 days of activation. Plan your training timeline backward from that deadline.

Can I bring notes into the GREM exam after training?

Yes, the exam is open book, allowing hardcopy books, notes, and an index. Internet access, personal electronic references, and practice-question collections are prohibited.

What happens if my training doesn't prepare me enough to pass the first time?

You can retake the exam for $899 after a mandatory 30-day waiting period, giving you time to target specific weak domains before your next attempt.

Whichever preparation route you choose, effective GREM training comes down to matching lab time and reference materials to the 15 published domains and the exam's specific hands-on format. Review the GREM Cheat Sheet 2026: One-Page Review of Must-Know Facts once your core training is complete to consolidate what you've learned before scheduling your attempt.

Ready to pass your GREM exam?

Put this into practice with free GREM questions across every exam domain.