SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsProve you can analyze Windows malware, bypass anti-analysis defenses, and reverse-engineer malicious documents and code.

The GIAC Reverse Engineering Malware (GREM) certification validates a practitioner's ability to examine the inner workings of malware in the context of forensic investigations, incident response, and Windows system administration. It proves the skills to reverse-engineer malicious software targeting common platforms, including Microsoft Windows and web browsers.
Exam duration
Questions
Min. passing score
GREM's 15 published objectives group into six practical domains, matching FOR610's six course sections.
Malware Analysis Fundamentals, Static Analysis Fundamentals, and Behavioral Analysis Fundamentals.
Core Reverse Engineering Concepts, Reversing Functions in Assembly, Malware Flow Control and Structures, and Common Malware Patterns.
Analyzing Malicious Office Macros, Analyzing Malicious PDFs, and Analyzing Malicious RTF Files.
Analyzing Obfuscated Malware, Unpacking and Debugging Packed Malware, and Examining .NET Malware.
Identifying and Bypassing Anti-Analysis Techniques and Overcoming Misdirection Techniques.
All 15 objectives applied in a hands-on capture-the-flag tournament.
FOR610: Reverse-Engineering Malware: Malware Analysis Tools and Techniques
FOR610 is built around the exam objectives that make up the GIAC Reverse Engineering Malware (GREM) certification:
Across all six sections, 48 hands-on labs and a capstone Malware Analysis Tournament give you the chance to apply each skill against real-world malware before you sit the exam.


Lenny Zeltser is a cybersecurity executive with technical roots, product management experience, and a business mindset. A SANS Fellow and REMnux creator, he has built security products and programs from early stage to enterprise scale.
Learn more

Anuj Soni, Principal Reverse Engineer at United Healthcare, has over 15 years of experience enhancing organizational security postures. His expertise has led to the identification, containment, and remediation of multiple threat actor groups.
Learn more
It validates a practitioner's ability to examine the inner workings of malware in the context of forensic investigations, incident response, and Windows system administration.
1 proctored exam, 66 questions, 3 hours, with a minimum passing score of 73%.
GIAC certifications are renewed on a recurring cycle through continuing education credits and a maintenance fee. For the current renewal requirements, see GIAC’s renewal page.
Incident responders, forensic investigators, technologists formalizing informal malware analysis experience, system and network administrators, and threat intelligence professionals. See the Who It's For section above for the full list.
Add the GREM exam attempt when you register for FOR610.
Already trained? Register for the exam directly through GIAC here.