And if the threat loads a driver that hides all its files? Or even just loads its data into an ADS on a normal file? A human really can't keep up with modern threats, even if it's a 24-hour job. Automated tools are required to be even reasonably secure.

