Wireshark's GeoIP feature launches an OpenStreetMap view of the world from the Endpoints window to plot IP addresses seen in the trace file.
The capture filter port 67 would capture all DHCP traffic seen by Wireshark.
An unusually high number of RSTs or a high number of SYN/ACKs with no related data transfer is a strong indication that a TCP scan is underway.