Tuesday, March 17, 2026

Zillow Preview Just Launched. Here's Why eXp Agents Are Already Ahead.

Zillow Preview Just Launched. Here's Why eXp Agents Are Already Ahead. 
March 17, 2026 | Jeff Stutzman, Monadnock Cyber Realty | eXp Realty NH


Today, Zillow announced Zillow Preview — a pre-market listing phase that lets agents display upcoming homes on Zillow and Trulia before they hit the MLS. Keller Williams, RE/MAX, HomeServices of America, United Real Estate, and Side signed on as founding partners.

This is a big move. And it's worth understanding what it means — and what it doesn't mean — for those of us at eXp.

What Zillow Preview Does

  • Agents at participating brokerages can post "Preview Listings" before MLS entry
  • Buyers see these listings with special placement and labeling
  • Buyers can save, share, and pre-schedule tours for go-live day
  • Free leads go directly to the listing agent (no Zillow lead fee)
  • If a Preview lead closes with a different Zillow partner agent, the listing agent gets a 10% referral from the buyer side

What This Really Is

Zillow Preview is a billboard. It gives agents a place to display a listing early. That's valuable — 230 million monthly visitors is no joke.

But a billboard only works if you already have the listing.

The harder question — the one Zillow Preview doesn't answer — is: How do you find the seller in the first place?

What We're Building at Monadnock Cyber

While the big brokerages are figuring out where to display listings, we've been building the system that identifies sellers before they know they're selling.

Our platform scans 92 independent sources nationwide every morning — public records, government registries, verified commercial data, and proprietary market models — and runs them through an AI-driven analysis engine. The output:

  • 828,000+ properties valued across a 4-method automated valuation model
  • Underpriced and overpriced properties flagged daily — GREEN (opportunity), RED (overpriced), YELLOW (fair value)
  • Distress signals detected automatically — tax liens, probate, divorce, relocation, code violations, estate sales
  • Owner contact enrichment — verified through government registry data and enhanced contact verification
  • DNC compliance built in — every phone checked against federal Do Not Call before any outreach

This isn't a listing tool. It's an intelligence platform. By the time a property shows up on Zillow Preview, we've already identified the owner, assessed the property's true value against multiple independent methods, and — in many cases — started the conversation.

The eXp Advantage

eXp wasn't named as a founding partner for Zillow Preview. Some agents may see that as a disadvantage. I see it differently.

We don't need Zillow to find our deals. We find them ourselves — earlier, with more data, and with full context on the owner's situation. If the listing eventually goes on Zillow Preview through a partner brokerage? Fine. But our agents already had the intelligence weeks before it got there.

The real competition in real estate isn't about who has the best billboard. It's about who has the best radar.

What This Means For You

If you're an eXp agent and you want access to:

  • The Stutzman Report — Monday morning intelligence briefing covering the top underpriced and overpriced properties in your market
  • Pre-market seller identification — distress signals, propensity scoring, and owner profiles before the property ever hits MLS
  • Verified owner contact data — DNC-compliant, multi-source validated
  • AI-driven market analysis — automated valuation on 828K+ properties across multiple states

Reach out. We're building this for eXp agents who want to operate with better intelligence than anyone else in their market.

Jeff Stutzman Monadnock Cyber, LLC | eXp Realty jstutzman@monadnockcyber.ai | (603) 930-2222 https://refax.pro


Monadnock Cyber is a real estate intelligence operation built on automated collection, AI-driven analysis, and multi-source validation. We don't scrape. We don't guess. We verify. Information is derived from public records, verified commercial sources, and proprietary intelligence models.

Saturday, February 21, 2026

Stop Overpaying for Real Estate. We're Watching.

Stop Overpaying for Real Estate. We're Watching.

You just paid $1.75 million for a house in XXXXXX, Connecticut.

Congratulations. It's worth $1.22 million.

You overpaid by 43.5%. That's $530,000 you lit on fire because your agent "felt good about the comps" and your lender rubber-stamped a number that made their commission work.

Nobody told you. Nobody was looking. Nobody cared — because everyone in that transaction got paid whether you got a fair deal or not.

We care. And we're looking at everything.


We Built the Machine That Catches This

At Monadnock Cyber, we don't sell houses. We sell intelligence.

While the rest of the real estate industry is still pulling comps from a 3-ring binder and calling it "market analysis," we built an automated valuation system that cross-references four independent pricing methodologies on every property we track:

  • Method A — MLS comparable sales analysis (what similar properties actually sold for)
  • Method B — Municipal assessment data, adjusted by state equalization ratios (what the town thinks it's worth, corrected for political math)
  • Method C — Skip trace equity modeling (what the financial footprint says)
  • Method D — Transfer price indexing (what the deed actually recorded)

When those four numbers agree, we have high confidence. When they don't, someone's getting taken for a ride.

We color-code every property:

  • GREEN — Underpriced. The seller left money on the table. The buyer got a deal.
  • YELLOW — Fair value. Both sides can sleep at night.
  • RED — Overpriced. Someone paid too much. Period.
  • GREY — Insufficient data. We don't guess.

The Numbers Don't Lie. People Do.

Right now, we're actively tracking 38,967 property valuations across 15 states and DC, fed by 1.67 million distress signals from 33 independent data sources. This isn't a weekend hobby. This is an intelligence operation.

Here's what we found in just the last seven days:

671
Properties Overpriced
RED — in 7 days
$942M
Collectively Overpaid
One week of data

That's not a typo. Nearly a billion dollars in unnecessary cost — in seven days — just in the properties we've valued so far. Imagine what a full year looks like.

That's one week. One. The machine never stops collecting.

Wall of Shame

LocationPaidActually WorthOverpaid By
XXXXXX, NH$1,266,78332.2%
XXXXXX, CT$1,387,63834.0%
XXXXXX, CT$1,219,52943.5%
XXXXXX, CT$1,120,78647.2%
XXXXXX, WV$18,732,36345.2%

That NH property? Lakefront New Hampshire. Beautiful area. Terrible deal. Someone paid $408,000 more than they should have because nobody in the room had independent valuation data.


This Isn't Just New Hampshire

We started in the Lakes Region. Now we're everywhere that matters.

PennsylvaniaConnecticutNew YorkMarylandVirginiaNorth CarolinaArizonaWest VirginiaWashington, DCVermontColoradoMaineMassachusettsNew Hampshire

You think Manhattan commercial real estate is priced rationally? We found a "luxury hotel" property in  valued at $111 million that traded at $260 million. That's a 134% premium. Somebody's CFO should be asking questions (OR FIRED!).

This is what happens when buyers rely on the same people selling the deal to also validate the deal.
It's the fox guarding the henhouse, and the fox is wearing a blazer.

How We're Different

Traditional real estate runs on three things: gut instinct, motivated reasoning, and information asymmetry. The agent knows more than you. The seller knows more than you. The lender just wants to close.

We flip that model. Our system:

  • Runs 24/7. Automated collectors pull data from public records, MLS feeds, municipal assessments, and federal registries while you sleep.
  • Uses four independent valuation methods — not one, and not the Zestimate. All four must converge before we call a property fairly priced.
  • Covers 158 million+ U.S. properties. That's 99% of the U.S. population's real estate footprint.
  • Flags overpriced deals in real time. Before you wire the money. Before the ink dries.
  • Has no commission bias. We don't get paid more when you pay more. Novel concept in this industry.

The Intelligence Advantage

Here's what the billion-dollar Wall Street firms already know: real estate is an information game. The party with the best data wins. Blackstone doesn't buy a strip mall because the listing agent said it's a "great opportunity." They run the numbers. Multiple numbers. From multiple sources.

You deserve the same advantage.

We call it REFAX — Real Estate Financial Analysis, Cross-Referenced. Every property gets a color. Every color is backed by math. Every decision you make is informed by data, not by someone who gets 3% of whatever you pay.


What This Means for You

If you're buying: You should know the real value before you bid. Not the listing price. Not the "estimated market value" your agent pulled from a single source. The actual, multi-method, cross-referenced value.

If you're selling: You should know exactly where your property sits. GREEN means you're priced to sell fast. RED means your agent priced it to maximize their commission, not your outcome. YELLOW means you're in the zone.

If you're investing: You should be looking at our GREEN list. Properties where the math says there's value the market hasn't priced in yet. That's not speculation — that's arbitrage.


We're Not Done

Residential. Commercial. Land. We value all of it. And we're moving quickly into business brokering and M&A — because the same information asymmetry that lets someone overpay for a lakehouse also lets someone overpay for a company.

38,967 valuations is the starting point. We're expanding coverage weekly. More states. More property types. More asset classes. The goal is simple: make information asymmetry a thing of the past.

The industry won't like it. They never do when someone turns the lights on.

But here's the thing — we're not asking permission.

Jeff Stutzman is the founder of Monadnock Cyber Intelligence and Monadnock Cyber (NH). He spent 35+ years in intelligence and cybersecurity before deciding the real estate industry needed the same treatment. He was right.

Have a property you want valued? Think you overpaid? Contact us — we'll tell you the truth, even if your agent won't, even if you don't like it.

Thursday, February 12, 2026

Superhuman Intelligence: How Beadwindow Delivers Hours of SOC Analysis in Milliseconds

Seven analytical engines, all firing in parallel, all showing their work -- and the SOC analyst walks into a finished intelligence product instead of a raw data dump. The Machine is doing more analytical work in 200ms than most commercial SIEMs do in their entire investigation workflow. That's what Superhuman Intelligence is all about.

The Problem Every SOC Analyst Knows

You're staring at an alert. "AI Detection: Port Scanning -- HIGH." The badge is red. The IP is 192.168.1.1. Now what?


If you're a human analyst, the next 45 minutes look something like this:

  1. Open a terminal. Run whois 192.168.1.1. Realize it's RFC-1918. Close the terminal.

  2. Check the DHCP table. Figure out it's the gateway.

  3. Open Wireshark. Filter by IP. Wait for it to load. Scroll through 6,000 flows.

  4. Notice 24 unique destination ports. Manually count them.

  5. Open the MITRE ATT&CK Navigator. Search for T1046. Read the technique description.

  6. Check if this IP has been seen before. Query the SIEM. Wait. Scroll. Count.

  7. Check the firewall logs. Did Firewalla see this? Did the ASA block it?

  8. Check if any external IPs were involved. Parse through NAT translations.

  9. Correlate timestamps. Build a timeline. Write it up.

  10. Brief your team lead.

That's an hour of work. Per alert. And you have 800 more in the queue.-----What If the Machine Did All of That -- On Every Alert -- Before You Even Clicked?


That's what Beadwindow v12 does. When you click into an alert investigation page, seven analytical engines fire simultaneously. By the time the page renders -- roughly 200 milliseconds later -- you're looking at the finished intelligence product.


Not raw data. Not a log dump. A synthesized assessment with reasoning.


Here's what the system produces for that same port scanning alert, automatically:Neural Analysis


Anomaly Score: 0.85

Models Used: mranv/siem-llama-3.1:v1 (Fred, SIEM Analyst)


Threat Indicators:

 - 20 ports scanned from single source [HIGH]

   "Horizontal port scanning indicates network reconnaissance"

 - 1 unique target host [LOW]

   "Single target -- could be targeted attack or service probe"

 - MITRE ATT&CK: T1046 (Network Service Discovery) [HIGH]

   "Behavioral pattern matches known adversary technique"

 - Detection confidence: 40% [MEDIUM]

   "Confidence derived from behavioral pattern matching against known attack signatures"

 - Source: 192.168.1.1 [INFO]

   "Originating IP captured from SPAN port mirror on USW-Pro-48"


Every indicator comes with a reason. Not just "what" -- why.


AI Assessment with Full Reasoning Chain"Detection engine identified Port Scanning originating from 192.168.1.1. Mapped to MITRE ATT&CK T1046 (Network Service Discovery) -- this technique is used by adversaries to enumerate network services and identify exploitable entry points. Observable evidence: 20 ports probed, 1 target host. Fred (SIEM Analyst, siem-llama-3.1) scored 85/100: HIGH confidence threat requiring immediate SOC attention. Ethel (Risk Analyst) has not yet validated this finding -- single-model assessment only. FLAGGED: Queued for manual SOC analyst review and triage."


This isn't a template. It's generated dynamically from the actual evidence, AI scores, MITRE mapping, and verdict state of each individual alert. Different alert? Different narrative. Every time.Network Evidence: PCAP-Level Pattern Analysis


The system pulls 50 related network flows and analyzes them for patterns:


PORT SCAN: 24 unique destination ports contacted --

 indicates systematic service enumeration


MULTI-TARGET: traffic to 9 distinct hosts --

 suggests automated scanning or lateral movement


Protocol breakdown: UDP: 29 flows, TCP: 21 flows


Data volume: 51.9 KB transferred (51.9 KB out, 0.0 KB in)


That asymmetric traffic pattern (51.9 KB out, 0.0 KB in) tells its own story -- outbound probing with no responses. Classic reconnaissance.Source Intelligence: Who Is This IP?


This is where it gets interesting. The system doesn't just tell you the IP address. It tells you who it is:


192.168.1.1

 [RFC-1918 Internal] [Ubiquiti USG/Gateway] [gateway]

 Reverse DNS: unifi.localdomain

 Behavior: High port and destination diversity -- consistent with

   NAT gateway or router (6,037 outbound flows, 6,805 inbound,

   4,711 unique dest ports)

 Alert History: 800 alerts (Port Scanning: 600, Reconnaissance: 200)

   First seen: 2026-02-10 | Last seen: 2026-02-11


For an internal IP, the system automatically traces external contacts -- who was this host talking to outside the network in the 30-minute window around the alert? It enriches each external contact with reverse DNS, Firewalla GeoIP data, and cross-references against the alert database.


For an external IP like 160.79.104.10 (150 alerts on file), the intelligence is even more pointed:


160.79.104.10

 [Public Internet] [scanner]

 Reverse DNS: none (hiding behind privacy/CDN)

 Behavior: Elevated port diversity suggests scanning or enumeration

 Targeted internal hosts: 192.168.1.102 (Mac Mini M4 SIEM) -- 132 flows


An external IP with no reverse DNS, scanner behavior, and 132 flows aimed directly at our SIEM server. That's actionable intelligence. That's a candidate for an abuse notification to the ISP. That's a future SWARM escalation target. IOC Cross-Referencing..


Every alert is automatically correlated against:

  • The alert corpus: "This IP has appeared in 800 total alerts"

  • Block actions: "IP was blocked via auto-response on 2026-02-10"

  • Firewall logs: "Firewall observed 47 flows, actions: allow. GeoIP: US"

  • Behavioral indicators: "20 ports scanned targeting 1 host -- moderate intensity"

Full Event Timeline


Not just "alert created." A complete chain of custody:

  1. SPAN Capture: "SPAN port (en11) captured suspicious traffic from 192.168.1.1 via USW-Pro-48 port mirror"

  2. Detection: "Alert generated: AI Detection: Port Scanning"

  3. Fred Analysis: "Fred (AI SIEM Analyst) completed analysis -- threat score: 85/100. HIGH confidence: attack pattern matches known signatures."

  4. AI Verdict: "Flagged for MANUAL REVIEW -- analyst must confirm or dismiss."

If a block action was taken, it's in the timeline. If an audit log entry exists, it's there. The full story, chronologically, with severity ratings on every event.-----The Philosophy: Show Your Work


Here's the thing about AI in security operations. The industry has spent years building black boxes. "Trust the score." "It's AI." "The algorithm detected it."


That's not good enough for a SOC.


When a human analyst investigates an alert, they build a mental model. They trace connections. They form hypotheses. They document their reasoning. And when they brief their team lead, they don't say "the score was 85." They say why.


Beadwindow v12 does the same thing. Every score has a reason. Every indicator has context. Every assessment has a narrative. The AI doesn't just detect -- it explains.


This isn't about replacing analysts. It's about giving them the finished product so they can make decisions instead of doing data entry.


The difference between a Level 1 analyst and a Level 3 analyst isn't knowledge -- it's speed. A Level 3 knows what to look for and where to find it. Beadwindow gives every analyst Level 3 speed on every alert, from their first day.-----The Numbers


Task

Human Analyst

Beadwindow v12

Identify source IP role

5-10 min

Instant

Reverse DNS + GeoIP

2-5 min

2 seconds

MITRE technique mapping

5-10 min

Instant

Network flow analysis

15-30 min

Instant

IOC cross-referencing

10-20 min

Instant

External contact tracing

15-30 min

Instant

Build investigation timeline

10-15 min

Instant

Write assessment narrative

10-15 min

Instant

Total

~90 minutes

~200 ms

That's not an optimization. That's a paradigm shift.-----What's Next?


This is the foundation. The source intelligence pipeline is ready for:

  • Abuse notifications: Automated emails to ISP abuse contacts for US-based providers hosting scanners

  • SWARM escalation: AI-coordinated multi-model threat hunting and defense on high-confidence alerts --2ndAmendmentCyber.

  • Temporal analysis: "This IP scans us every Tuesday at 3 AM" -- pattern-of-life detection

  • Reputation scoring: Aggregated threat scores that improve over time as the corpus grows

The alert investigation page isn't just a viewer anymore. It's the SOC analyst's co-pilot.-----Beadwindow is an on-premise SIEM/XDR platform built on FastAPI, running on Apple Silicon, with dual-AI analysis (Fred + Ethel), SPAN port capture, and synthesized intelligence that shows its work. Every alert. Every time.


By Jeffery Stutzman, Beadwindow Project, https://2ndAmendmentCyber.com

"F**KIN A"