- What Counts as GREM Training
- FOR610 Training vs. Self-Study Preparation
- Mapping Training to the 15 GREM Domains
- Training for the Exam Format Itself
- Building a Malware Analysis Lab
- A Domain-Sequenced Training Timeline
- Training Costs and Registration Mechanics
- Who Pursues GREM Training and Why
- Frequently Asked Questions
- GIAC lists three prep routes for GREM: SANS FOR610 training, practical work experience, or self-paced study.
- The exam is 66 questions in 3 hours with a 73% passing score, mixing multiple-choice and CyberLive VM tasks.
- Exam-only registration is $999; training itself is purchased separately from the certification attempt.
- All 15 published domains, from Office macros to unpacking, deserve dedicated lab time, not just reading.
What Counts as GREM Training
GREM training refers to the preparation work a candidate does before sitting the GIAC Reverse Engineering Malware exam. GIAC does not require candidates to take a specific course before registering for the exam. Instead, GIAC publishes three acceptable preparation routes: formal training through the associated course, practical work experience in malware analysis, and self-paced study using books, whitepapers, and lab practice. Whichever route you choose, "training" for GREM ultimately means building hands-on reverse-engineering skill across the 15 published domains, not memorizing trivia.
Because the exam draws from a specific set of certification objectives, effective training is structured around those objectives rather than around generic security topics. If you haven't reviewed the objectives in detail yet, the GREM Exam Domains 2026: Complete Guide to All 15 Content Areas breaks down what each domain actually tests, which is the natural starting point before you build a study plan.
FOR610 Training vs. Self-Study Preparation
The training most commonly associated with GREM is SANS FOR610: Reverse-Engineering Malware: Malware Analysis Tools and Techniques. This course is GIAC's listed associated training for the certification, and it's built to walk through the same categories of skill the exam objectives cover, from static analysis to behavioral analysis to unpacking. Taking the associated course gives you structured labs and an instructor-guided path through material that otherwise takes significant self-direction to assemble.
That said, GIAC explicitly recognizes practical work experience and self-paced study as valid alternatives. If you already work in malware analysis, incident response, or a SOC role that involves disassembly and debugging, your day-to-day experience may already cover several domains. In that case, training time is better spent filling specific gaps - for example, .NET malware analysis or anti-analysis bypass techniques - rather than repeating skills you already use at work.
For a candid look at how demanding this preparation actually is regardless of route, see How Hard Is the GREM Exam? Complete Difficulty Guide 2026, which walks through the skill gap between general security knowledge and the reverse-engineering depth GREM expects.
Key Takeaway
Choose your training route based on your current skill gaps, not on what's most popular. Someone who already debugs malware daily needs different training than someone entering reverse engineering for the first time.
Mapping Training to the 15 GREM Domains
GIAC publishes 15 domain headings for GREM, and each one represents a distinct skill set an examiner expects you to demonstrate - often through a hands-on CyberLive task rather than a simple recall question. Training that ignores any of these areas leaves a real gap on exam day.
Domain 1: Analyzing Malicious Office Macros
Candidates need to extract and de-obfuscate VBA macros, identify malicious API calls, and trace execution from document open to payload delivery.
- Practice with real macro-enabled document samples in an isolated VM
Domain 2 & 3: Analyzing Malicious PDFs and RTF Files
These formats require understanding embedded objects, JavaScript execution paths, and exploit-delivery structures unique to each file type.
- Train on extracting embedded streams and objects with static-analysis tooling
Domain 4, 9 & 12: Obfuscation, Anti-Analysis, and Misdirection
These three domains overlap heavily in practice. Training should cover recognizing packers, string obfuscation, anti-debugging checks, and techniques malware authors use to mislead an analyst.
- Build familiarity with common obfuscation patterns before attempting timed labs
Domain 7 & 13: Core Reverse Engineering Concepts and Assembly Functions
This is the foundational layer underneath every other domain. Weak assembly-reading skills will slow you down across the entire exam.
- Drill function prologues, calling conventions, and control-flow reconstruction in a disassembler
Domain 8: Examining .NET Malware
.NET binaries decompile differently than native code, and training here should include working with decompilers built for managed code rather than treating every sample as native x86.
- Practice recovering readable source-like logic from .NET assemblies
Domain 15: Unpacking and Debugging Packed Malware
Packed samples are common in real malware, and this domain tests whether you can identify a packer, set breakpoints strategically, and dump unpacked code for further analysis.
- Rehearse manual unpacking workflows, not just automated unpacker tools
Domains 5, 6, 10, 11, and 14 - Behavioral Analysis Fundamentals, Common Malware Patterns, Malware Analysis Fundamentals, Malware Flow Control and Structures, and Static Analysis Fundamentals - form the connective tissue that ties the more specialized domains together. Training time here should focus on building a repeatable analysis methodology you can apply consistently across sample types. For a complete walkthrough of how these 15 areas interrelate, revisit the GREM Exam Domains 2026: Complete Guide to All 15 Content Areas.
Training for the Exam Format Itself
Domain knowledge alone isn't sufficient - part of GREM training is getting comfortable with the exam's specific format. The exam is web-based and proctored, delivered through either ProctorU remote proctoring or Pearson VUE test centers depending on how your attempt is authorized. It consists of 66 questions to be completed in 3 hours, combining traditional multiple-choice questions with hands-on CyberLive virtual-machine tasks where you interact with a live environment rather than just selecting an answer.
The minimum passing score is 73%. Because the exam is open book - hardcopy books, notes, and an index are permitted, though internet access, personal electronic devices, and practice-question collections are prohibited - training should include building a well-organized physical index you can navigate quickly under time pressure. An exam that allows references but limits you to 3 hours across 66 items rewards fast retrieval far more than memorization.
The exam engine also provides a built-in calculator and scratch notepad - small tools, but worth practicing with in any mock exam environment you build, since fumbling with unfamiliar interface elements costs real minutes. For a deeper breakdown of exactly what 73% means in practice and how the scoring works, see GREM Passing Score 2026: Exactly What You Need to Pass.
Building a Malware Analysis Lab
No amount of reading substitutes for hands-on time inside a disassembler, debugger, and decompiler, especially given how many CyberLive tasks appear on the exam. A functional home lab for GREM training typically includes:
- An isolated virtual machine environment for safely detonating and observing malware samples
- A disassembler and debugger for static and dynamic native-code analysis
- A .NET decompiler for Domain 8 preparation
- Tools for extracting and analyzing Office macros, PDF objects, and RTF structures
- A packing/unpacking workflow you can repeat consistently for Domain 15
Set up this lab early in your training timeline rather than during the final review weeks. Troubleshooting tool configuration under exam-week pressure wastes time that should go toward actual sample analysis.
A Domain-Sequenced Training Timeline
Generic study techniques like spaced repetition or timeboxed review sessions only help when they're mapped onto GREM's actual domain structure. Below is one way to sequence training across several weeks, prioritizing foundational domains before specialized ones.
Foundations
- Core Reverse Engineering Concepts, Static Analysis Fundamentals, Malware Analysis Fundamentals
- Set up lab tooling and practice basic disassembly
Assembly and Behavior
- Reversing Functions in Assembly, Behavioral Analysis Fundamentals, Malware Flow Control and Structures
Document-Based Threats
- Analyzing Malicious Office Macros, PDFs, and RTF Files
- Practice extraction and de-obfuscation on real samples
Evasion and Advanced Topics
- Analyzing Obfuscated Malware, Identifying and Bypassing Anti-Analysis Techniques, Overcoming Misdirection Techniques
- Unpacking and Debugging Packed Malware, Examining .NET Malware
Integration and Timed Practice
- Common Malware Patterns review, full-length timed practice runs, index refinement
This sequencing is only a starting framework - adjust the pacing to your background. For a more detailed week-by-week strategy including how to allocate review time near the end of your attempt window, see the GREM Study Guide 2026: How to Pass on Your First Attempt.
Training Costs and Registration Mechanics
Understanding the fee structure helps you plan training investment realistically. The exam-only certification attempt is $999 USD before taxes, and training is purchased separately from that fee. If your first attempt doesn't succeed, a retake costs $899, and a mandatory 30-day waiting period applies before you can sit again - which makes thorough training before your first attempt more valuable than rushing in and relying on a retake.
GIAC also offers a standalone official practice test for $399, useful as a diagnostic tool to identify weak domains before exam day, and an attempt extension for $479 if you need more time within your access window. Once your attempt is activated, you have 120 days to complete it, and your candidate account will display the attempt-specific exam specifications relevant to your registration.
| Item | Cost |
|---|---|
| Exam-only certification attempt | $999 USD |
| Retake (after failed attempt) | $899 |
| Standalone official practice test | $399 |
| Attempt extension | $479 |
| CPE renewal (every 4 years, 36 CPEs required) | $499 |
For a full breakdown of every fee alongside training cost considerations, read GREM Certification Cost 2026: Complete Pricing Breakdown. And if you're still confirming that your background meets what's expected before registering, check GREM Requirements 2026: Eligibility, Prerequisites & How to Qualify.
Who Pursues GREM Training and Why
GREM training tends to attract malware analysts, incident responders, threat intelligence analysts, and digital forensics professionals who need to move from "detecting" malware to actually dissecting it. Because the certification centers on reverse engineering rather than broad security operations, it appeals specifically to people whose job requires reading disassembled code, tracing obfuscated logic, and unpacking samples by hand - not generalist security roles.
If you're evaluating whether this specialization fits your career path before committing training time and exam fees, Is the GREM Certification Worth It? Complete ROI Analysis 2026 and GREM Jobs both cover how the credential is used in practice. For a look at how the role and skill set typically translate into compensation, see GREM Salary Guide 2026: Complete Earnings Analysis.
Once your training is well underway, it's worth running full practice attempts under realistic time constraints. You can find a broader set of practice resources on the main practice test site to simulate the pacing of a 66-question, 3-hour attempt before you commit to a real registration date.
Key Takeaway
Training that mirrors the exam's mix of multiple-choice and CyberLive tasks will expose weaknesses that flashcards alone never will. Prioritize lab time over passive reading in your final weeks.
Frequently Asked Questions
No. GIAC lists FOR610 as the associated training course, but practical work experience and self-paced study are also recognized preparation routes for the GREM exam.
No. The exam-only certification attempt is $999 USD before taxes, and any training course is purchased separately.
You must complete your exam attempt within 120 days of activation. Plan your training timeline backward from that deadline.
Yes, the exam is open book, allowing hardcopy books, notes, and an index. Internet access, personal electronic references, and practice-question collections are prohibited.
You can retake the exam for $899 after a mandatory 30-day waiting period, giving you time to target specific weak domains before your next attempt.
Whichever preparation route you choose, effective GREM training comes down to matching lab time and reference materials to the 15 published domains and the exam's specific hands-on format. Review the GREM Cheat Sheet 2026: One-Page Review of Must-Know Facts once your core training is complete to consolidate what you've learned before scheduling your attempt.