Certification guide

GREM

GIAC Reverse Engineering Malware (GREM): the honest guide

Everything GIAC publishes about GREM, in one place: what the exam asks, how the domains are weighted, and what it takes to be ready.

This guide page is built from the registry, not written yet.

Everything below comes from GREM’s published exam data, and every figure links to the vendor page it came from. The researched version, with study plans and the parts nobody publishes, is still being written. This page is not submitted to search engines until it is.

See everything published on GREM

What the exam actually asks you to do

A CyberLive exam. Some of the questions put you into a live machine with the real tools and score what you do there. GIAC does not publish how many of the 66 are hands-on, so neither do we.

Item formats

  • Multiple choice
  • Hands-on lab

The highlighted formats are the ones you cannot answer from memory alone. GIAC, GREM certification details

Domain breakdown

Malware Analysis and Reverse Engineering Fundamentals is the heaviest domain at 22 percent, followed by Malicious Document Analysis at 18 percent.

GIAC publishes the GREM objectives as an unweighted list covering malware and behavioral analysis fundamentals, core reverse engineering concepts, static analysis, reversing functions in assembly, flow control and structures, malicious Office macros, PDFs and RTF files, obfuscated malware, anti-analysis and misdirection techniques, unpacking and debugging packed malware, common malware patterns, and .NET malware. It attaches no percentages. The six groupings above and their percentages are ours, a study aid rather than an official GIAC weighting, and GIAC does not endorse them.

  • Malware Analysis and Reverse Engineering Fundamentals22%
  • Assembly and Code Structures16%
  • Malicious Document Analysis18%
  • Anti-Analysis and Obfuscation18%
  • Unpacking and Debugging Packed Malware14%
  • Common Malware Patterns and .NET Malware12%

Where to focus: GREM's 73 percent pass mark is among the highest GIAC sets, and the CyberLive items drop you into a debugger rather than a multiple choice list. Build a safe analysis VM and reverse real samples: recognising a packer or an anti-analysis check by its behaviour is faster under the clock than working it out from first principles.

GIAC: GIAC certification objectives

What comes after passing

GREM is valid for 4 years. GIAC certifications last four years. GIAC lists two renewal routes: collect 36 CPE credits over the four year cycle and pay the renewal fee, or retake the current exam. Additional renewals within two years of a full price renewal are charged at a reduced rate.

Costs across the full renewal cycle are on the GREM cost page.

Frequently asked questions

What does the GREM exam cost?

GIAC's pricing page lists a GIAC certification attempt at $999. The certification attempt can be bought on its own, without a training course.

Is the GREM exam hands-on?

GIAC tags GREM as a CyberLive certification. GIAC describes CyberLive as a hands-on format that replaces multiple choice with performance-based challenges in lab environments using virtual machines and real tools. The exam format section lists 1 proctored exam, 66 questions, 3 hours, and a minimum passing score of 73%.

Are there prerequisites for GREM?

GIAC's GREM page lists no prerequisite, though the material assumes comfort with assembly and a debugger. Under How To Prepare it points to training in a variety of modalities, practical work experience, and self study.

Keep reading

  • GREM exam overview

    The format, the domain weights and the renewal terms, sourced line by line.

  • GREM passing score

    The exact cut score, what kind of number it is, and the retake terms.

  • How hard is GREM?

    An honest difficulty read from the format, the clock and the weights.

Every guide and cost breakdown, by vendor