No one has built a better mousetrap than Wireshark yet.
I would ask your IT team to have a Wireshark Sniffer set to get data from the handset AND the SIP gateway. Easiest way is a build a computer with 2 NICS and install Wireshark on it. Then plug the NIC's into different ports on a switch, then span the ports for the Gateway and the handset to the sniffer's ports and run Wireshark from there. The other helpful tip is to have the Phone and the Gateway on the same switch.
PCAP analysis is best done after you captured all the raw data. Don't try to do it in real time. So set your environment up, get your relevant IP's, and maybe run a few test Captures to see what your baseline traffic looks like. Then get your problem child to make a call and run the PCAP at the same time.
-Ian