Mitigating Advanced Persistent Threats in Resource-Constrained Environments: Design and Implementation of a Lightweight Endpoint Detection and Response (EDR) Framework for Small-Scale Enterprises
DOI:
https://doi.org/10.5281/zenodo.21450399Keywords:
advanced persistent threats, endpoint detection and response, lightweight EDR, small-scale enterprises, MITRE ATT&CK, endpoint telemetry, cybersecurity metricsAbstract
Advanced Persistent Threats (APTs) continue to represent one of the most significant cybersecurity challenges because of their ability to maintain persistent, covert access to target systems while evading conventional security mechanisms (Akbar et al., 2023; Hutchins et al., 2011). The prolonged dwell time and sophisticated attack strategies employed by APT actors often result in substantial operational, financial, and reputational damage before compromise is detected. Micro and small enterprises are particularly susceptible to these threats due to constrained cybersecurity budgets, limited security infrastructure, and insufficient personnel dedicated to continuous monitoring and incident response (Blancaflor et al., 2024; Department of Information and Communications Technology [DICT], 2023). Although commercial Endpoint Detection and Response (EDR) solutions provide comprehensive endpoint visibility and automated threat detection, their acquisition, deployment, and maintenance costs frequently exceed the operational capacity of resource-constrained organizations (Blancaflor et al., 2024).
This study designed, developed, and evaluated a lightweight Endpoint Detection and Response framework specifically intended for micro and small enterprise environments. The proposed framework integrates endpoint telemetry collection, behavioral process monitoring, trust-based process assessment, rule-based detection using YARA and Sigma signatures, external cyber threat intelligence enrichment, heuristic-assisted anomaly detection, dynamic risk scoring, centralized event logging, and dashboard-based incident management to facilitate timely threat detection and analysis. The research adopted the Design Science Research Methodology (DSRM) proposed by Peffers et al. (2007), following the iterative phases of problem identification, objective definition, design and development, demonstration, evaluation, and communication. Functional and usability evaluation was conducted by five purposively selected domain experts, comprising three information technology personnel and two system administrators, using the ISO/IEC 25010 software quality model. Technical validation was performed within a controlled small-enterprise testbed using MITRE ATT&CK-aligned adversary emulation scenarios, safe malware test artifacts, and a labeled dataset consisting of 512 endpoint events, including 68 malicious and 444 benign activities (MITRE ATT&CK, n.d.; Sikorski & Honig, 2012).
The evaluation results demonstrated that the proposed framework achieved” Highly Evident” ratings across all assessed ISO/IEC 25010 quality characteristics, including functional suitability, performance efficiency, compatibility, reliability, security, maintainability, flexibility, and safety. Comparative analysis of the pre-implementation and post-implementation evaluations showed a statistically significant improvement in the overall weighted mean score from 2.41 (Moderately Evident) to 3.55 (Highly Evident) (p < 0.001, n = 5). Cybersecurity performance evaluation further indicated robust detection capability, correctly identifying 66 true positives and 435 true negatives while producing only 9 false positives and 2 false negatives. These outcomes correspond to a detection accuracy of 97.85%, precision of 88.00%, recall of 97.06%, false positive rate of 2.03%, and false negative rate of 2.94%. Furthermore, the framework maintained an average detection and response time of 1.8 seconds, average CPU utilization of 4.6%, and average memory consumption of 105 MB, indicating that effective endpoint monitoring and APT detection can be achieved with minimal computational overhead.
Overall, the findings demonstrate that the proposed lightweight EDR framework provides an effective and resource-efficient approach for strengthening endpoint security in micro and small enterprises. By combining behavioral monitoring, signature-based detection, threat intelligence integration, and heuristic analysis within a lightweight architecture, the framework enhances endpoint visibility and supports the timely detection of APT-related activities while maintaining low resource consumption. These results suggest that the proposed solution represents a practical alternative to commercially available EDR platforms for organizations operating under resource constraints.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Aloysian Interdisciplinary Journal of Social Sciences, Education, and Allied Fields

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
