Specifically, forensic device 12 obtains an Internet Protocol (IP) address within the subnet scope of the LAN to which target computing device 16 is connected either dynamically via a protocol such as Dynamic Host Configuration Protocol (DHCP) or statically via configuration by a network administrator.