First, we can tell if a key is coming from a keygen or not (because we have all keys that were legally purchased in our database).
Next, we can also tell if a key is being misused. I mean, if it's a key for 1 license of avast Pro and the update requests are coming from 20,000 different machines in 120 domains, we can be pretty sure the key was published somewhere on the Internet
