Certification guide
GREMGIAC Reverse Engineering Malware (GREM): the honest guide
Everything GIAC publishes about GREM, in one place: what the exam asks, how the domains are weighted, and what it takes to be ready.
This guide page is built from the registry, not written yet.
Everything below comes from GREM’s published exam data, and every figure links to the vendor page it came from. The researched version, with study plans and the parts nobody publishes, is still being written. This page is not submitted to search engines until it is.
See everything published on GREMWhat the exam actually asks you to do
A CyberLive exam. Some of the questions put you into a live machine with the real tools and score what you do there. GIAC does not publish how many of the 66 are hands-on, so neither do we.
Item formats
- Multiple choice
- Hands-on lab
The highlighted formats are the ones you cannot answer from memory alone. GIAC, GREM certification details ↗
Domain breakdown
Malware Analysis and Reverse Engineering Fundamentals is the heaviest domain at 22 percent, followed by Malicious Document Analysis at 18 percent.
GIAC publishes the GREM objectives as an unweighted list covering malware and behavioral analysis fundamentals, core reverse engineering concepts, static analysis, reversing functions in assembly, flow control and structures, malicious Office macros, PDFs and RTF files, obfuscated malware, anti-analysis and misdirection techniques, unpacking and debugging packed malware, common malware patterns, and .NET malware. It attaches no percentages. The six groupings above and their percentages are ours, a study aid rather than an official GIAC weighting, and GIAC does not endorse them.
- Malware Analysis and Reverse Engineering Fundamentals22%
- Assembly and Code Structures16%
- Malicious Document Analysis18%
- Anti-Analysis and Obfuscation18%
- Unpacking and Debugging Packed Malware14%
- Common Malware Patterns and .NET Malware12%
Where to focus: GREM's 73 percent pass mark is among the highest GIAC sets, and the CyberLive items drop you into a debugger rather than a multiple choice list. Build a safe analysis VM and reverse real samples: recognising a packer or an anti-analysis check by its behaviour is faster under the clock than working it out from first principles.
What comes after passing
GREM is valid for 4 years. GIAC certifications last four years. GIAC lists two renewal routes: collect 36 CPE credits over the four year cycle and pay the renewal fee, or retake the current exam. Additional renewals within two years of a full price renewal are charged at a reduced rate.
Costs across the full renewal cycle are on the GREM cost page.
Frequently asked questions
What does the GREM exam cost?
GIAC's pricing page lists a GIAC certification attempt at $999. The certification attempt can be bought on its own, without a training course.
Is the GREM exam hands-on?
GIAC tags GREM as a CyberLive certification. GIAC describes CyberLive as a hands-on format that replaces multiple choice with performance-based challenges in lab environments using virtual machines and real tools. The exam format section lists 1 proctored exam, 66 questions, 3 hours, and a minimum passing score of 73%.
Are there prerequisites for GREM?
GIAC's GREM page lists no prerequisite, though the material assumes comfort with assembly and a debugger. Under How To Prepare it points to training in a variety of modalities, practical work experience, and self study.
Keep reading
- GREM exam overview
The format, the domain weights and the renewal terms, sourced line by line.
- GREM passing score
The exact cut score, what kind of number it is, and the retake terms.
- How hard is GREM?
An honest difficulty read from the format, the clock and the weights.