Memory can reveal what disk cannot

A great deal of what matters during an intrusion exists only while the machine is running.

Running processes, network connections, decrypted data, credentials, and malware that never touches the disk at all. Turn the machine off and all of it is gone permanently. This is why the instinct to immediately power down a compromised machine, which feels decisive, frequently destroys the only evidence that would have explained anything.

More on Digital forensics