For pentesting-related packages, your best bet may be to create a KaliVM which is debian based. I’ve ran there metasploit without a problem. (one warning, though, if you wish to establish reverse-shells, you’ll need to mess with the firewal or something like this)
The easiest way I find it by cloning the debian template, replacing the package repos to kali’s and dist-upgrading it to kali: