Actually, you should be able to tcpdump as soon as whatever sends the DHCP requests starts doing so, as it must UP the interface to do anything useful. I routinely dump on a device with no address... every time my cable modem loses sync, it eventually loses its address, and tcpdump is useful for "well, is it just me, or what?"
And unless this is a boot-time-only problem, you shouldn't have to make hijack do anything more weird than fork tcpdump at the right time; you can have the player up and some partition mounted read/write, and then plug in the ethernet cable.