Pentesting thick clients can be done in the following two ways:
Pentesting Java Thick Applications with Burp JDSer: https://www.netspi.com/blog/entryid/67/pentesting-java-thick-applications-with-burp-jdser
"Reversing" Non-Proxy Aware HTTPS Thick Clients w/ Burp: http://blog.spiderlabs.com/2014/02/reversing-non-proxy-aware-https-thick-clients-w-burp.html