If you want repeatable results, you need a very deep understanding of how AV and EDR works ranging from kernelcallbacks to etw to userland hooks and stack/thread telemetry. You can learn these things by reading yes, but I learn a lot more by getting my own hands dirty.