That isn't how torrent sites work. You visit site.xyz and download a .torrent file in the realm of 10s-100s (typically) of kB and that contains some metadata that a dedicated torrent client consumes. The torrent client connects to (1) some tracker via http (or https, but usually http) which may or may not be associated with the site the .torrent came from, to register as part of the swarm, and (2) any number of peer torrent clients. The actual data (X GiB) transfer comes from those peers; not the original site.xyz nor the tracker.
ISPs can observe DNS lookups / connections to site.xyz; tracker "announces" (that's (1) above), especially if they are http. And even the peer-to-peer traffic has a distinct protocol which is recognizable with packet inspection. But the main avenue for finding offenders, I believe, is just downloading the same .torrents for some specific copyrighted content and using the torrents' associated tracker(s) to enumerate swarm peer IP addresses.