Numerous security incidents caused by malwaresand hackers have recently utilized anti-forensic techniquesto bypass analysis and detection. It is critical to build aknowledge base that would help understand such anti-forensictechniques. In this paper, we present a forensic analysis methodto detect an anti-forensic technique which leverages timestampmanipulation in NTFS file system. Our approach analyzeshow timestamp manipulation occurs in NTFS file system andalso extracts some features to detect timestamp manipulationbehaviors. We also evaluate our approach with several usecases and describe how our approach helps detect timestampmanipulation behaviors.