CFP last date
20 August 2026
Reseach Article

RedKit: A Lightweight Penetration Testing Framework using Docker-based Isolation

by Mohammed Abdelfattah, Youssef Hamdy Abdelazeem, Mohamed Mahmoud Hanafi, Ziad Mahmoud Mohamed, Abdallah Waleed Ab-delmajeed, Ahmed Mamdouh Salem
International Journal of Computer Applications
Foundation of Computer Science (FCS), NY, USA
Volume 187 - Number 106
Year of Publication: 2026
Authors: Mohammed Abdelfattah, Youssef Hamdy Abdelazeem, Mohamed Mahmoud Hanafi, Ziad Mahmoud Mohamed, Abdallah Waleed Ab-delmajeed, Ahmed Mamdouh Salem
10.5120/ijca077168be4e15

Mohammed Abdelfattah, Youssef Hamdy Abdelazeem, Mohamed Mahmoud Hanafi, Ziad Mahmoud Mohamed, Abdallah Waleed Ab-delmajeed, Ahmed Mamdouh Salem . RedKit: A Lightweight Penetration Testing Framework using Docker-based Isolation. International Journal of Computer Applications. 187, 106 ( May 2026), 27-34. DOI=10.5120/ijca077168be4e15

@article{ 10.5120/ijca077168be4e15,
author = { Mohammed Abdelfattah, Youssef Hamdy Abdelazeem, Mohamed Mahmoud Hanafi, Ziad Mahmoud Mohamed, Abdallah Waleed Ab-delmajeed, Ahmed Mamdouh Salem },
title = { RedKit: A Lightweight Penetration Testing Framework using Docker-based Isolation },
journal = { International Journal of Computer Applications },
issue_date = { May 2026 },
volume = { 187 },
number = { 106 },
month = { May },
year = { 2026 },
issn = { 0975-8887 },
pages = { 27-34 },
numpages = {9},
url = { https://ijcaonline.org/archives/volume187/number106/redkit-a-lightweight-penetration-testing-framework-using-docker-based-isolation/ },
doi = { 10.5120/ijca077168be4e15 },
publisher = {Foundation of Computer Science (FCS), NY, USA},
address = {New York, USA}
}
%0 Journal Article
%1 2026-05-21T00:16:55.333131+05:30
%A Mohammed Abdelfattah
%A Youssef Hamdy Abdelazeem
%A Mohamed Mahmoud Hanafi
%A Ziad Mahmoud Mohamed
%A Abdallah Waleed Ab-delmajeed
%A Ahmed Mamdouh Salem
%T RedKit: A Lightweight Penetration Testing Framework using Docker-based Isolation
%J International Journal of Computer Applications
%@ 0975-8887
%V 187
%N 106
%P 27-34
%D 2026
%I Foundation of Computer Science (FCS), NY, USA
Abstract

RedKit is a Security as a Service (SECaaS) platform designed to facilitate penetration testing across the entire life cycle through a microservices architecture. RedKit includes both manual and automated testing. In manual testing, RedKit offers custom-built Docker containers as a pre-configured environment that includes a web proxy ready for testing. In automated testing, RedKit features an AI-driven vulnerability scanner to automate repetitive tests, reducing the effort required of penetra-tion testers. RedKit includes information gathering, reconnaissance tools, and AI report generation. RedKit integrates all these features into a cloud-based, all-in-one framework, a low-effort solution for end-to-end security assessments. By integrat-ing Docker and merging automated testing with manual testing, RedKit builds a full penetration testing framework with mini-mal resource overhead. By accomplishing 60% of resource management and 90% of time saving for setting up the environment.

References
  1. ENISA, “ENISA Threat Landscape 2024,” 2024. [Online]. Availa-ble:https://www.enisa.europa.eu/publications/enisa-threat-landscape-2024
  2. R. Morabito, J. Kjällman, and M. Komu, “Hypervisors vs. lightweight virtualization: A performance comparison,” in Proc. IEEE Int. Conf. on Cloud Engineering (IC2E), 2015, pp. 386–393, doi:10.1109/IC2E.2015.74.
  3. V. Lazarov, P. Seda, Z. Martinasek, and R. Kummel, “Penterep: Comprehensive penetration testing with adapt-able interactive checklists,” Computers & Security, vol. 154, p. 104399, 2025. [Online]. Availa-ble:https://www.sciencedirect.com/science/article/pii/S0167404825000884
  4. S. S. Patil and S. S. Shinde, “Analysis of Penetration Testing Tools,” in Proc. Int. Conf. on Inventive Research in Computing Applications (ICIRCA), 2018. [Online]. Availa-ble:https://www.researchgate.net/publication/326077274
  5. PortSwigger, “Burp Suite: The class-leading vulnerability scanner,” [Online]. Available: https://portswigger.net/burp
  6. OWASP Foundation, “OWASP Zed Attack Proxy (ZAP),”[Online]. Available: https://www.zaproxy.org/
  7. A. Riancho, “w3af: Web Application Attack and Audit Framework,”[Online]. Available: https://github.com/andresriancho/w3af
  8. PTES, “Penetration Testing Execution Standard (PTES),”[Online]. Available: http://www.pentest-standard.org/
  9. K. Scarfone, M. Souppaya, A. Cody, and A. Orebaugh, “Technical Guide to Information Security Testing and As-sessment (NIST SP 800-115),” NIST, 2008. [Online]. Available: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-115.pdf
  10. Docker Inc., “Docker Documentation,” [Online]. Availa-ble: https://docs.docker.com/
  11. S. Ramirez, “FastAPI framework, high performance, easy to learn,”[Online]. Available:https://fastapi.tiangolo.com
  12. IETF, “RFC 6455: The WebSocket Protocol,” [Online]. Available: https://datatracker.ietf.org/doc/html/rfc6455
  13. d'Itri, M. (2026). whois: Intelligent WHOIS client (Ver-sion 5.5) [Computer software]. GitHub. https://github.com/rfc1036/whois
  14. A. Sykes, “Web-Check: All-in-one OSINT tool for ana-lyzing any website,” [Online]. Available: https://github.com/Lissy93/web-check
  15. R. Halley, “dnspython: A DNS toolkit for Python,” [Online]. Available:https://www.dnspython.org/
  16. Sectigo, “crt.sh: Certificate Search,” [Online]. Available: https://crt.sh/
  17. Nmap Project, “Nmap: Free Security Scanner, Port Scan-ner, & Network Exploration,” [Online]. Available: https://nmap.org
  18. Jaeles Project, “GoSpider: Fast web spider written in Go,” [Online].Available: https://github.com/jaeles-project/gospider
  19. T. Nomnom, “Waybackurls: Fetch all the URLs that the Wayback Machine knows about for a domain,” [Online]. Available: https://github.com/tomnomnom/waybackurls
  20. Internet Archive, “Wayback Machine API,” [Online]. Available: https://archive.org/web/
  21. Kasm Web, “Kali Rolling Desktop Docker Image,” Dock-er Hub. [On-line]. Available: https://hub.docker.com/r/kasmweb/kali-rolling-desktop
  22. Offensive Security, “Kali Linux Penetration Testing OS,” [Online].Available: https://www.kali.org/
  23. Kanaka, “noVNC: HTML5 VNC Client,” [Online]. Available: https://novnc.com/
  24. TigerVNC Project, “High-performance, platform-neutral VNC,” [On-line]. Available: https://tigervnc.org/
  25. A. Cortesi, M. Hils, and T. Kriechbaumer, “mitmproxy: A free and open source interactive HTTPS proxy,” [Online]. Available: https://mitmproxy.org/
  26. Anthropic, “Model Context Protocol Specification,” [Online]. Available:https://modelcontextprotocol.io/
  27. Google DeepMind, “Gemini: The most capable AI mod-els,”[Online]. Available: https://deepmind.google/technologies/gemini/
  28. Cohere Inc., “Cohere LLM Documentation,” [Online]. Available: https://cohere.com/
  29. Oracle Corporation, "Oracle VM VirtualBox," [Online]. Available: https://www.virtualbox.org/
  30. Aristocratos, "btop: Resource monitor," [Online]. Availa-ble: https://github.com/aristocratos/btop
  31. PostgreSQL Global Development Group, “PostgreSQL Documentation,”[Online]. Available: https://www.postgresql.org/docs/
  32. Redis Ltd., “Redis Documentation,” [Online]. Available: https://redis.io/docs/latest/
  33. Kubernetes Authors, “Kubernetes Documentation,” [Online].Available: https://kubernetes.io/docs/
Index Terms

Computer Science
Information Sciences

Keywords

Containerization Penetration Testing Web Proxy SECaaS (Security as a Service) Methodology LLM Reporting Pay-loads Ethical Hacking Docker