Persistence
Once an attacker is in, their next priority is usually not stealing anything. It is making sure they can get back in.
That means finding somewhere to hide that survives a reboot, a password change or the machine being rebuilt: a scheduled task, a modified setting, an extra account, a mail rule. It is why "we removed the malware" is an incomplete answer. If the way back in is still there, the malware coming back is not a new incident, it is the same one continuing, and it is why response work has to include looking for what was left behind.
Checked against the primary source.
