Building Burp Extensions with Kotlin

Nick Coblentz

BSides NYC 2024 · Day 1 · Tech - Red

This presentation, delivered by Nick Coblentz, a seasoned application penetration tester and PortSwigger Discord moderator, delves into the advantages and practicalities of developing Burp Suite extensions using Kotlin. The talk addresses a common frustration among penetration testers: the time-consuming and repetitive manual tasks involved in security assessments, often exacerbated by the perceived complexity and overhead of building custom Burp extensions. Coblentz makes a compelling case for Kotlin as a more enjoyable and efficient alternative to Java for this purpose.

AI review

Competent, practitioner-focused talk that delivers real value to appsec testers who want to stop copy-pasting JWTs and start writing actual tooling. The Kotlin pitch is honest and the released artifacts — template, examples, settings/UI library — are the talk's strongest contribution. Nothing here will make a researcher sit up, but it solves a genuine friction point for its target audience.

Watch on YouTube