Objectivity is the discipline of forming conclusions from the evidence rather than selecting evidence to fit a conclusion.
Explanation
In forensic work, ego is the enemy. The desire to "catch the bad guy" can quietly bias which evidence an investigator collects, which they ignore, and how they interpret ambiguous artifacts. Objectivity counters this by treating every conclusion as provisional until the evidence supports it — and by actively seeking evidence that would disprove it. The operative question is not "does the data support my theory?" but "what would I expect to see if my theory were wrong, and have I looked for it?"
Objectivity also means separating observation from interpretation. "This connection was established at 03:12 UTC" is an observation; "this proves the attacker exfiltrated data" is an interpretation that must survive comparison with benign alternatives — software updates, misconfigured services, normal user behavior. A finding that cannot be tested against a reasonable alternative is not a finding; it is a guess with paperwork.
Finally, objectivity is what makes your work defensible. A conclusion reached through a biased process may occasionally be right, but it cannot be trusted, repeated, or survive cross-examination. Document what you looked for, what you excluded, and why — so another analyst following the same process would reach the same conclusion.
Examples
- An investigator suspects a host is beaconing to a C2 server. Instead of collecting only the outbound flows that match the expected pattern, she pulls the host's full netflow history and tests benign explanations (NTP, update services, misconfigured agents) against the malicious one, documenting why each was ruled out.
- A peer reviewer is asked to argue the opposite conclusion from the same artifacts. If the opposite case remains plausible, the original conclusion was under-supported.