Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS)

GIAC Reverse Engineering Malware

The GIAC Reverse Engineering Malware (GREM) certification validates your ability to analyze and reverse-engineer malicious software targeting common platforms like Microsoft Windows and web browsers. Designed for technologists who protect their organizations from malicious code, GREM proves you can examine malware's inner workings in the context of forensic investigations, incident response, and Windows system administration. Earning GREM demonstrates hands-on, real-world malware analysis skills that are essential for defending against today's threats.

Exam formatCyberLive: Hands-on testing with performance-based challenges in realistic lab environments
Duration180 minutes
DeliveryGIAC
Passing score73%
Free questions593

Content last reviewed 30 July 2026 · Up to date

The certification

What GIAC Reverse Engineering Malware proves, and what it asks of you

What this certification covers, who it is written for, and what the exam itself looks like on the day.

5domains
15objectives
117concepts
What it is

What this certification is

What it validates, who it is written for, and the experience it assumes.

About this certification

The GIAC Reverse Engineering Malware (GREM) certification validates a practitioner's ability to examine the inner workings of malware in the context of forensic investigations, incident response, and Windows system administration. It is designed for technologists who protect their organizations from malicious code, showing that these individuals possess the knowledge and skills to reverse-engineer malicious software that targets common platforms, such as Microsoft Windows and web browsers.

GREM covers malware analysis using code and behavioral analysis fundamentals, Windows Assembly concepts for reverse engineering, in-depth analysis of malicious executables and self-defending malware, and analysis of malicious document files, .NET programs, and protected executables. The certification is delivered through GIAC's CyberLive format, which replaces traditional multiple-choice testing with performance-based challenges in realistic lab environments, validating real-world capability with virtual machines, real security tools, and authentic code.

Who it’s for

The GREM certification is for system and network administrators, auditors, security consultants and managers, and technologists looking to formalize and expand their expertise in malware analysis. It is also ideal for forensic investigators and security practitioners looking to expand their skillsets, as well as individuals who have dealt with incidents involving malware. If you are responsible for protecting your organization from malicious code and need to understand how malware works to defend against it, GREM provides the validation you need.

Recommended experience

Practical work experience in information security, particularly in areas related to malware analysis, incident response, or system administration, is recommended. College-level courses or self-paced study through other programs or materials may also help you master the necessary skills. Experience with Windows system administration and common malware characteristics; Familiarity with basic programming concepts and assembly language; Understanding of network protocols and web technologies; Exposure to forensic investigations or incident response processes

The syllabus

What you’ll learn

Every domain and objective GIAC (SANS) measures, with the weight they carry on the exam.

The official GIAC (SANS) exam outline · checked 30 July 2026 · See the source

Malware Analysis Fundamentals
  • Malware Analysis Fundamentals
  • Behavioral Analysis Fundamentals
  • Static Analysis Fundamentals
3 objectives · 123 free questions · 26 pages
Core Reverse Engineering Concepts
  • Core Reverse Engineering Concepts
  • Reversing Functions in Assembly
  • Malware Flow Control and Structures
3 objectives · 88 free questions · 19 pages
Malware Patterns and Obfuscation
  • Common Malware Patterns
  • Analyzing Obfuscated Malware
  • Overcoming Misdirection Techniques
3 objectives · 130 free questions · 27 pages
Document and File Analysis
  • Analyzing Malicious Office Macros
  • Analyzing Malicious PDFs
  • Analyzing Malicious RTF Files
3 objectives · 139 free questions · 30 pages
Advanced Malware Analysis
  • Examining .NET Malware
  • Unpacking and Debugging Packed Malware
  • Identifying and Bypassing Anti-Analysis Techniques
3 objectives · 113 free questions · 24 pages
On the day

The exam itself

Everything GIAC (SANS) publishes about sitting it, and nothing we inferred.

Prerequisites

No mandatory prerequisites — this certification has no required predecessor exam or credential.

CertificationGIAC Reverse Engineering Malware
Exam formatCyberLive: Hands-on testing with performance-based challenges in realistic lab environments
Duration180 minutes
Questions66 questions
Passing score73%
DeliveryGIAC
LanguagesEnglish
After you pass

Where this credential goes next

The path GIAC (SANS) lays out, how the credential is kept, and where to book.

Step-by-step path to GIAC Reverse Engineering Malware

GIAC Reverse Engineering Malware badgeCredential earnedGIAC Reverse Engineering Malware Certification
Renewal and maintenance

GIAC certifications must be renewed every four years by earning 36 CPE credits or retaking the exam. Stay current with the latest technologies and maintain your certification.

Learn more about renewal requirements
Lifecycle status

This certification is currently active and available. GIAC (SANS) maintains this certification to validate current skills and industry relevance.

Exam status: ActiveMaintained by GIAC (SANS)

Exam registration

Register for the exam through GIAC, GIAC (SANS)’s authorized testing partner.

Schedule your exam

Visit the official GIAC (SANS) certification page for exam policies and requirements.

View the official page
Your coach

And when you are serious, your coach Pip takes over

Your coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.

See how the coach works
Before you book

Questions people ask

How does the GREM exam relate to other GIAC certifications?

GREM is a Practitioner-level certification. It can be combined with other GIAC certifications to build a portfolio toward the GIAC Security Professional (GSP) or GIAC Security Expert (GSE) credentials.

Is the GREM exam hands-on?

Yes, the GREM exam uses the CyberLive format, which includes performance-based challenges in realistic lab environments with virtual machines, real security tools, and authentic code.

How do I schedule my GREM exam?

After your application is approved and payment is processed, your certification attempt is activated in your GIAC account. You will receive an email notification and can then schedule your proctored exam through GIAC's delivery partners.

What are the proctoring options for the GREM exam?

GIAC offers two proctoring options: remote proctoring through ProctorU and onsite proctoring through PearsonVUE.

How long do I have to complete my GREM exam attempt after registration?

You have 120 days from the date of activation to complete your certification attempt.

What job roles does the GREM certification map to?

GREM is designed for system and network administrators, auditors, security consultants and managers, forensic investigators, and security practitioners who deal with malware incidents.

Can I renew my GREM certification by passing a different GIAC exam?

Yes, GIAC allows renewal by retaking the GREM exam or by earning 36 CPE credits. Passing a different GIAC exam may also earn CPE credits toward renewal.

Are there any regional restrictions for taking the GREM exam?

GIAC exams are available globally through remote proctoring and onsite proctoring at PearsonVUE test centers, subject to availability.

Information freshness · Content last reviewed on 2026-07-30 Up to date
Practice free questions 593 questions, free, no account needed.