On 14.03.2017 13:41, Florentin Rochet wrote:
/"It is running a Tor Exit, hence producing a false positive." is not a valid reason.//
Well yeah, it's not a "false positive". That "you cannot do anything about it" might not be the best argument here either: I suggest you block the destination IP address(es) for some weeks via ExitPolicy, let the sender of the complaint konw that you will remove the block again in X weeks, while putting your ISP in CC. Then you can use that as the argument that you "took care of it" and that you don't accept "illegal actions" either.
Then, another possible argument in most cases is that what is being reported is not "illegal activity", but merely a notification about some event that triggered some IDS (port scanning, script-kiddie/metasploit stuff, etc). Ultimately it will be hard to argue why a scan does not automatically mean that it is "illegal" these days, but it might help in certain discussions.