Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS)

GIAC Reverse Engineering Malware

GREM

The GIAC Reverse Engineering Malware (GREM) certification validates your ability to analyze and reverse-engineer malicious software targeting common platforms like Microsoft Windows and web browsers. Designed for technologists who protect their organizations from malicious code, GREM proves you can examine malware's inner workings in the context of forensic investigations, incident response, and Windows system administration. Earning GREM demonstrates hands-on, real-world malware analysis skills that are essential for defending against today's threats.

593 practice questions · Updated 2026-07-30

5Domains
15Objectives
117Concepts
593Questions

GREM Curriculum

Every domain, objective, and concept the GREM exam measures.

Malware Analysis Fundamentals

1 concepts · 28 questions
  1. Malware Analysis Fundamentals

Behavioral Analysis Fundamentals

10 concepts · 46 questions
  1. Behavioral Analysis Definition
  2. Static vs. Dynamic Behavioral Analysis
  3. Setting Up a Safe Analysis Environment
  4. Observing File System Activity
  5. Observing Registry Activity
  6. Observing Process and Service Activity
  7. Observing Network Activity
  8. Using System Monitoring Tools
  9. Automated Sandbox Analysis
  10. Documenting Behavioral Findings

Static Analysis Fundamentals

11 concepts · 49 questions
  1. Static Analysis Overview
  2. File Identification
  3. Hashing
  4. String Extraction
  5. Packing and Obfuscation Detection
  6. PE Header Analysis
  7. Import and Export Table Analysis
  8. Section Analysis
  9. Resource Analysis
  10. Anti-Analysis Techniques
  11. Static Analysis Tools

Core Reverse Engineering Concepts

1 concepts · 15 questions
  1. Core Reverse Engineering Concepts

Reversing Functions in Assembly

8 concepts · 32 questions
  1. Function Prologue and Epilogue
  2. Calling Conventions
  3. Stack Frame Layout
  4. Argument Passing and Access
  5. Local Variable Allocation
  6. Return Value Handling
  7. Control Flow within Functions
  8. Function Calls and Disassembly

Malware Flow Control and Structures

10 concepts · 41 questions
  1. Control flow analysis
  2. Structured exception handling (SEH)
  3. Calling conventions
  4. Function prologues and epilogues
  5. Switch-case and jump tables
  6. Loop structures
  7. Conditional branches and flags
  8. Opaque predicates
  9. Control flow flattening
  10. Indirect calls and pointers

Common Malware Patterns

8 concepts · 43 questions
  1. Common Malware Patterns Overview
  2. Persistence Mechanisms
  3. Privilege Escalation Patterns
  4. Defense Evasion Patterns
  5. Command and Control (C2) Patterns
  6. Lateral Movement Patterns
  7. Data Exfiltration Patterns
  8. Malware Lifecycle Stages

Analyzing Obfuscated Malware

8 concepts · 43 questions
  1. Obfuscation Techniques Overview
  2. Static Analysis of Obfuscated Code
  3. Dynamic Analysis of Obfuscated Code
  4. Deobfuscation Strategies
  5. Tools for Analyzing Obfuscated Malware
  6. Anti-Analysis Evasion Techniques
  7. Identifying Obfuscation Patterns
  8. Case Studies of Obfuscated Malware

Overcoming Misdirection Techniques

5 concepts · 44 questions
  1. Identify Misdirection Techniques
  2. Analyze Dead Code and Junk Instructions
  3. Detect Opaque Predicates
  4. Understand Control Flow Flattening
  5. Apply Deobfuscation Strategies

Analyzing Malicious Office Macros

11 concepts · 56 questions
  1. Office Macro Basics
  2. VBA Code Structure
  3. Macro Execution Triggers
  4. Obfuscation Techniques
  5. Malicious Payload Delivery
  6. Static Analysis of Macros
  7. Dynamic Analysis of Macros
  8. Anti-Analysis Techniques
  9. Document Metadata and Artifacts
  10. Macro Sandboxing and Emulation
  11. Indicators of Compromise (IOCs)

Analyzing Malicious PDFs

6 concepts · 36 questions
  1. PDF Structure Fundamentals
  2. Malicious PDF Detection Techniques
  3. JavaScript and Action Analysis in PDFs
  4. Exploit Identification in PDFs
  5. PDF Obfuscation and Evasion Methods
  6. PDF Analysis Tools and Automation

Analyzing Malicious RTF Files

10 concepts · 47 questions
  1. RTF File Structure
  2. Malicious RTF Indicators
  3. RTF Parsing Techniques
  4. Exploit Detection in RTF
  5. OLE Object Analysis
  6. Macro Analysis in RTF
  7. RTF Obfuscation Methods
  8. Sandboxing and Dynamic Analysis
  9. YARA Rules for RTF
  10. Reporting and Documentation

Examining .NET Malware

12 concepts · 57 questions
  1. .NET Assembly Structure
  2. Managed vs Unmanaged Code
  3. Decompiling .NET Assemblies
  4. Analyzing .NET Metadata
  5. Obfuscation Techniques in .NET
  6. Deobfuscating .NET Malware
  7. .NET Malware Execution Flow
  8. Interacting with .NET Runtime
  9. Packing and Unpacking .NET
  10. .NET Malware Persistence Mechanisms
  11. Dynamic Analysis of .NET Malware
  12. Anti-Analysis Techniques in .NET

Unpacking and Debugging Packed Malware

9 concepts · 31 questions
  1. Identify packed malware
  2. Static analysis of packed binaries
  3. Dynamic analysis setup for unpacking
  4. Manual unpacking with debuggers
  5. Automated unpacking tools
  6. Dumping and rebuilding the unpacked binary
  7. Debugging packed malware
  8. Handling anti-debugging and anti-VM techniques
  9. Analyzing unpacked code
  1. Detecting Anti-Analysis Techniques
  2. Bypassing Anti-Debugging
  3. Bypassing Anti-Virtualization
  4. Bypassing Anti-Disassembly
  5. Defeating Obfuscation
  6. Handling Anti-Analysis in Dynamic Analysis
  7. Handling Anti-Analysis in Static Analysis
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GREM, so none is invented.