Why?

Obfuscate names/paths (drop some malware in a system location and give it a legitimate name) Misspelled versions of proper system processes Proper process names in wrong location Duplicate processes that should only spawn once Processes that have a parent when they shouldn’t System processes with start time much later than boot-time System processes running under a user account
RAM is volatile
windows.pslistEPROCESS)windows.pstreeEPROCESS)windows.psscanwindows.dumpfiles --pid <PID>windows.memmap --dump --pid <PID>windows.dllist --pid <PID>windows.cmdlinewindows.envars [--pid <pid>]windows.handles --pid <pid>windows.registry.hivescanwindows.registry.hivelistwindows.registry.printkey -K "Path\To\Key"windows.filescanwindows.dumpfileswindows.dumpfiles --virtaddr <o>windows.dumpfiles --physaddr <o>windows.netscanwindows.netstatwindows.strings --strings-file ./strings_filewindows.vadyarascan --yara-rules "https://" --pid <PIDS>yarascan.YaraScan --yara-rules <R>windows.hashdumpwindows.cachedumpwindows.lsadump