Yes, even if someone blocks port scans, we can still detect server usage by checking the ISP type, which can reveal if an IP is likely used as a proxy.
Yes, we can still detect if someone is trying to hide server activity, even if they block port scans. Port scanning helps us identify whether a customer is running a web server, which may indicate that their IP is being used as a proxy. For a proxy to work, certain ports must be open. If those ports appear closed - possibly because they’re spoofed to evade detection - we can still assess the likelihood of proxy usage by analyzing the type of Internet Service Provider (ISP). Server-hosting ISPs are a strong signal that the IP might be used in this way.