An attack surface is everything about an organisation that an outsider can see and potentially target — domains, subdomains, exposed services, leaked credentials, and public employee information. Mapping it is a defensive OSINT exercise: teams enumerate their own attack surface before an adversary does.
The same techniques an attacker would use — footprinting, subdomain enumeration, breach checks — are turned inward to find and close exposures.