According to the iptables man page, SNAT/DNAT are valid ctstate options along with related/established/new/invalid. Of course this doesn't necessarily mean they are valid where needed in the firewall setup code, so I have no idea the difficulty or possibility of this.
It would be nice to be able to have a single firewall rule to allow all DNATed connections, instead of one rule per DNAT. Other platforms allow this and it eliminates a lot of repetition when it comes to creating destination NAT configurations.