Glossary
LOLBin
A legitimate, usually Microsoft-signed binary that attackers use to run or fetch code, such as rundll32, regsvr32, mshta or certutil.
"Living off the land" binaries are tools already present on Windows whose normal features can execute scripts, load DLLs or download files. The LOLBAS project catalogues them with examples. Common in scheduled task actions: rundll32.exe, regsvr32.exe, mshta.exe, wscript.exe, cscript.exe, certutil.exe, bitsadmin.exe and powershell.exe.
A LOLBin as a task command is a triage pointer, not a finding: the arguments decide. A DLL or script path in a user-writable folder is what turns it into a lead. See detecting malicious scheduled tasks.