You can prepare for most of the GREM exam with three free tools: REMnux for triage and network simulation, Ghidra for static code analysis, and x64dbg for debugging and unpacking. Between them they cover 14 of GIAC's 15 GREM objectives, and they are the tools SANS uses in its FOR610 course.
Which tool covers which GREM objective?
REMnux handles document malware and first-pass triage, Ghidra handles reading code, and x64dbg handles anything that needs the sample running. The map below is our own. The objective names come from GIAC.
- REMnux: malicious Office macros, PDFs and RTF files, obfuscated JavaScript, and the static and behavioral fundamentals. It is a Linux distribution packed with analysis utilities, so one virtual machine covers the whole document family.
- Ghidra: core reverse engineering concepts, flow control and structures, reversing functions in assembly, and common malware patterns. Its decompiler helps you check your reading of the assembly, but the exam objectives are written around assembly, so practise without it too.
- x64dbg: anti-analysis techniques, misdirection, and unpacking and debugging packed malware. These objectives only make sense with the code running under a debugger.
For .NET malware, you'll want a .NET decompiler as well. Samples decompile close to source, so this objective needs less time than native code.
How should the lab be set up?
Use two isolated virtual machines: one Windows guest for running samples with x64dbg and Ghidra, and one REMnux guest for tools and fake network services. Snapshot both before you open any malware.
A few rules save hours:
- Put both machines on a host-only network, with REMnux acting as the fake internet.
- Install every tool before the first sample touches the Windows guest.
- Roll back to the clean snapshot after each sample, even if nothing seemed to happen.
You can download Ghidra's source and releases from the NSA's GitHub repository.
What should you practise with each tool?
Match each tool to the skill the exam checks. With Ghidra, trace one function per day: its parameters, its return value and every call it makes. With x64dbg, set breakpoints on the API calls that unpackers commonly use, and practise dumping the unpacked image.
If you want these tool sessions laid out week by week, a six-week GREM study plan follows the objective families in order, from lab setup to timed practice.
This EduSum video covers preparation for GCFR, another GIAC exam in the forensics and incident-response track, and the prep approach carries over to GREM.
Frequently Asked Questions
1. What tools do I need for GREM?
REMnux, Ghidra and x64dbg cover the GREM objectives, and all three are free. Add a .NET decompiler for the .NET malware objective.
2. Is Ghidra enough for GREM static analysis?
Ghidra handles disassembly and decompiling, but practise reading raw assembly too, because the objectives focus on assembly-level reversing.
3. Do I need two virtual machines for a GREM lab?
Yes. A Windows guest runs the samples, and a REMnux guest provides tools and simulated network services on an isolated network.














