Payload obfuscation modifies payloads to evade AV/EDR signature detection — base64 encoding, XOR encryption, string concatenation, variable substitution, compression.
Obfuscation defeats signature-based detection but not behavioral detection. EDR watching for PowerShell making outbound connections will still fire even if the PowerShell script is heavily obfuscated. Focus obfuscation on static file analysis evasion; assume behavioral detection still catches execution.