Have you tried to set a trigger on TCP-Open ? I know the open did not finsih - but perhaps that would catch the attempt.
If you could then start an on-demand capture - you could catch the packet and the information being provided.
From the Help panel on Triggers : ->
Note: For TCP flows, the FLOW_CLASSIFY event runs after the TCP_OPEN event. <-
All though this note also applies -> TCP_OPEN Runs when the TCP connection is first fully established.
So - the key might be 'fully established' - - yours is only doing the first Syn and not fully established. But it is worth a try.