In network forensics, the footprint is the impact an investigator leaves on the systems under examination. Every interaction with a live system modifies it in some way—just as walking through a physical crime scene alters it. Network evidence is often volatile and must be collected actively, so the footprint can never be eliminated, only minimized and documented.

Key points from Network Forensics: Tracking Hackers through Cyberspace, §1.3:
- Investigators rarely have the luxury of an offline copy when dealing with network equipment or servers.
- Active acquisition inherently modifies the host system, even if only slightly.
- Techniques like port mirroring or cable tapping still have some environmental impact.
- The size of the footprint must be weighed against the need for speed in data collection.
- Record every action carefully so you can later demonstrate that important evidence was not modified.

"You will always leave a footprint. Always be conscious of your footprint and tread lightly."

This concept connects to the broader forensic principles of Evidence Preservation, Chain Of Custody, and Core Principles of Forensic Science.