I would have loved to a see a CTM light virtualization subfunction working at sector level and able to use RAM for its virtualization buffer. Like Shadow Defender on steroids.
All snapshots would be totally isolated from events in the virtual system. At the end of a session the user could choose to discard changes or keep changes as a new snapshot (or as an update to an existing snapshot.)
If it can also withstand TDSS rootkit infections (like Shadow Defender does) then Chuck Norris - along with the rest of us - would have surely approved it!