Doing some testing on new AV. Been reading a lot about custom payloads. I now many of these are old, but the ideas may still be new to others.
Here are some of the more recent reads ......
http://e-spohn.com/blog/2012/08/02/pe-crypters-hyperion/
https://www.christophertruncer.com/bypass-antivirus-with-meterpreter-as-the-payload-hyperion-fun/
http://www.exploit-monday.com/2011/11/powersyringe-powershell-based-codedll.html
http://colesec.inventedtheinternet.com/obfuscating-meterpreter-payloads-with-veil/
http://colesec.inventedtheinternet.com/hacking-with-powershell-powersploit-and-invoke-shellcode/
https://github.com/rapid7/metasploit-framework/wiki/How-payloads-work
https://www.citadelo.com/en/how-we-bypassed-nod32-and-hacked-a-paranoid-customer-2/