[ click anywhere to skip ]

guin@norrath:~$ whoami

securing information systems · defending against AI-accelerated attacks · automating risk ops

click anything to earn XP & level up your character

0 Projects
0 EverQuest Scripts
0 Years in Security

I Projects 18 artifacts

relics & artifacts forged by the dev — click one to inspect

II Infrastructure 6 nodes

the home stronghold — every node self-hosted

waf

Home-Built WAF

ServWall — a network web application firewall written in Go. Sits in line between clients and the origin, inspecting every request: declarative YAML rules, per-IP rate limiting, regex attack-pattern inspection, and an opt-in self-hosted local-AI verdict layer.

Go Declarative Rules Rate Limiting AI Inspection TLS / HTTP/3
node: servwaf
ai

Local AI

Self-hosted LLM services, no cloud.

OpenCode Qwen3.6 LocalAI StableDiffusion LiteLLM
node: gpu-box-01
ha

Home Assistant

Home automation & monitoring.

Automation Monitoring
node: ha-core
git

Gitea

Self-hosted Git server & CI/CD.

Git CI/CD
node: gitea:8443
vm

Virtual Machines

Multi-OS virtualization layer.

Debian Fedora Windows 95
node: kvm-host
db

Databases

Data services & persistence.

MariaDB SQLite RabbitMQ
node: db-cluster

III Cyber Risk prestige codex

A decade-plus of third-party cyber risk across diverse vendor ecosystems. Leading assessments, continuous monitoring, and AI risk evaluations from the front lines.

01

Leadership Capabilities

Leading cross-functional risk initiatives, mentoring junior risk analysts, presenting to executive leadership, and driving organizational maturity in third-party risk practices.

Team Leadership Executive Reporting Mentoring
02

Third Party Risk Assessments

End-to-end risk assessments of third-party vendors — evaluating security posture, identifying gaps, and delivering remediation roadmaps aligned to NIST and ISO frameworks.

NIST RMF ISO 27001 SOC 2 Questionnaires
03

Control Maturity

Maturing vendor security controls across the full lifecycle — from onboarding to ongoing reassessment, keeping continuous alignment with organizational risk tolerance.

CMMC Control Mapping Gap Analysis
04

Cyber Event Response

Coordinating incident response for third-party security events — detection through containment, notification, and post-incident remediation with full vendor accountability.

Incident Coordination Vendor Notification Remediation
05

Continuous Third Party Monitoring

Continuous monitoring programs tracking vendor security posture in real time — security ratings, breach alerts, compliance drift, and automated risk scoring.

Security Ratings Breach Alerts Automated Scoring
06

Third Party Inventory

Comprehensive third-party inventories with risk categorization, data-flow mapping, contract tracking, and automated refresh cycles keeping the vendor ecosystem fully visible.

Vendor Registry Data Flow Mapping Risk Tiering
07

Third Party AI Assessments

Specialized assessments for AI/ML vendors and AI-powered services — model risk, data governance, algorithmic bias, and AI-specific security controls in the third-party lifecycle.

Model Risk AI Governance Bias Evaluation Data Privacy

IV EverQuest Ecosystem server: online

preserving a beloved MMORPG, one quest at a time

EQEmulator Server

uptime: since 2009 // contributors: many

In 2006, a team of enthusiasts reverse-engineered EverQuest's server/client protocol to preserve a beloved game. I joined in 2009, contributing Perl, Lua, SQL, and RPG development. I host a personal instance for testing new features, and I'm building a 'Tour-de-Norrath' historical museum of the game.

Titanium Client ROF2 Client Lutris/Proton

Quest Development

280+ zones // lua & perl // ci/cd pipeline

EverQuest quests were nothing like modern MMORPGs — you won't find 'go kill 10 skeletons' here. They were impactful, meaningful, and often incredibly long. Rebuilding them has been a massive effort. We've even interviewed former EverQuest developers, artists, and producers to restore quests that are old, broken, or lost to time.

280+ Zones Lua & Perl CI/CD Pipeline

Spire

EverQuest custom server monitor web tool

status: online

ProjectEQ Database (PEQ)

The open-source database most servers utilize

rows: 10M+

AI Integration

Custom LocalAI-connected NPCs providing bespoke quests, using EQ databases as guides

model: local

V About character sheet

the traveler behind the codex

Nic Weilbacher

Systems Engineer & DevOps practitioner with a deep passion for building reliable infrastructure, automating operations, and securing networks. Thirteen years in cybersecurity — ten specializing in third-party cyber risk, plus three in vulnerability management and SOC. I bring a security-first mindset to everything I build, specializing in multi-service home datacenters, Kubernetes orchestration, and automation that turns manual toil into elegant solutions.

My work centers on Python automation, Third Party Cyber Risk, AI and Model Risk Management and AI-assisted system administration. I build network monitoring platforms with CIS compliance reporting, vulnerability assessment tools with LLM-driven analysis, and distributed task processing. I'm passionate about self-hosted services, private cloud infrastructure, and open-source tooling.

Off the clock, I'm tinkering — local AI models, RPG engines, retro-themed websites, and the occasional rabbit hole. I love learning across a broad range of topics and turning curious ideas into real, working projects.

Languages

Python 3.14 SQL Lua Perl Bash TypeScript

Infrastructure

Kubernetes Docker Nginx Caddy Gitea

Tools

nmap Paramiko LangChain Vue 3 Flask NIST

Domains

linuxelis.com norrath.org
LEVEL UP!
2
Apprentice
guin@norrath:~/console
guin@norrath:~$