Learn to take apart malicious software and understand exactly how it works the way professional malware analysts and threat researchers do. DronaShield's Malware Analysis course in Baner, Pune covers static and dynamic analysis, disassembly, debugging and sandboxing inside safe, isolated lab environments.
Every ransomware attack, banking trojan and advanced persistent threat starts with malicious code that someone eventually has to take apart and understand. DronaShield's Malware Analysis course in Baner, Pune teaches this reverse engineering discipline from the ground up, starting with safe lab setup and static analysis before progressing into dynamic analysis, disassembly and debugging.
The course covers malware types and behaviour, PE file format and Windows internals, static and dynamic analysis techniques, sandboxing, x86/x64 disassembly, debugging with x64dbg, unpacking and de-obfuscation, and specific modules on ransomware and fileless malware, anti-analysis techniques and persistence mechanisms attackers use to stay hidden.
Batches run in a hybrid format from our Baner campus, with students from Balewadi, Wakad, Hinjewadi, Aundh and Pashan attending evening or weekend sessions around existing jobs or studies. All practical work happens inside isolated, air-gapped lab environments built specifically for safe malware handling, and the course closes with a capstone project analysing a real sample end-to-end and writing a professional analysis report.
Graduates leave with a DronaShield Institute completion certificate, practical reverse engineering skills and a portfolio of analysis reports. Our placement cell works with job-ready students on resume reviews, mock interviews and introductions to hiring partners across Pune's growing threat research and DFIR industry.
Defenders who want to understand the malware behind the alerts they investigate.
Investigators who want to add deep malware reverse engineering to their DFIR skillset.
Programmers curious about low-level systems and reverse engineering as a specialisation.
Offensive security professionals who want to understand malicious code from the defender's side.
BCA, B.Tech, B.Sc and MCA graduates seeking a specialised, high-demand technical role.
Professionals from unrelated fields seeking a deeply technical path into cyber security.
Malware analysis is one of the more technical cyber security specialisations, so some prior exposure is helpful.
Analyse malicious samples to understand behaviour, capability and impact.
₹5 – 11 LPA*
Take apart binaries and firmware to understand functionality and vulnerabilities.
₹6 – 13 LPA*
Track malware families and campaigns to produce actionable threat intelligence.
₹6 – 14 LPA*
Combine malware analysis with incident response and forensic investigation.
₹6 – 13 LPA*
Specialise in triaging and analysing malware alerts within a security operations centre.
₹5 – 10 LPA*
Research vulnerabilities, exploits and emerging malware techniques.
₹6 – 15 LPA*
*Indicative salary ranges based on general industry postings for entry to mid-level roles in India. Actual compensation varies by employer, location and experience and is not guaranteed.
Twelve modules covering static and dynamic analysis, disassembly, debugging and specialised malware types, each reinforced with a hands-on lab.
Duration: Approximately 2 months, hybrid format combining classroom sessions, live online classes and self-paced lab access.
Batches: Weekday evening and weekend batches at our Baner, Pune campus.
Fees: Course fees vary by batch and any ongoing offers. Contact our admissions team for the current fee structure, EMI options and available scholarships.
This Malware Analysis course is led by certified trainers drawn from DFIR, SOC and VAPT industry backgrounds with hands-on reverse engineering experience. Sessions mix short theory blocks with long, supervised lab time inside isolated analysis environments, and trainers walk through real disassembly and debugging sessions so students see the thought process, not just the tools.
Every module in this course is reinforced with a lab exercise inside an isolated, air-gapped malware analysis environment. You will statically inspect a sample, detonate it safely in a sandbox, monitor its behaviour, step through disassembled code in a debugger, unpack an obfuscated sample, and finish with a capstone project analysing a real-world malware sample end-to-end and delivering a professional analysis report, exactly as expected on the job.
DronaShield's placement cell works with students throughout the Malware Analysis program, not just at the end. Support includes resume and LinkedIn profile reviews focused on malware analysis and threat research roles, mock technical interviews and report-review sessions, and introductions to our hiring partners as students become job-ready. Explore verified outcomes from past batches on our Placements page.
See real, named placement outcomes on our homepage placements section.
| Aspect | Malware Analysis | Digital Forensics |
|---|---|---|
| Focus | Reverse engineering malicious code to understand behaviour and capability | Broad investigation of an incident across disk, memory, mobile and network evidence |
| Best for | Those wanting deep, technical reverse engineering work | Those wanting to investigate incidents and support legal cases |
| Format at DronaShield | 2 months, hybrid, disassembly-lab heavy | 3 months, hybrid, investigation-lab heavy |
| Typical next step | Malware analyst, reverse engineer roles | DFIR analyst, cyber crime investigation roles |