How is it caviar then?
Just as an example: you use a mechanism similar to psexec to execute commands on the remote system using the SMB service. If the remote system has a capable EDR, it will shut that down and report the system from which the connection came from to the SOC, perhaps automatically isolate it. If it doesn't, an attacker moves laterally through your entire network with ease in no time until they have domain admin privs.
Running beacons with good EDRs is difficult, and has become the most challenging aspect of most red team engagements because of that.
No EDR, everything becomes suddenly super easy.